
- #Torrent site for installer el capitan mac os x install#
- #Torrent site for installer el capitan mac os x software#
#Torrent site for installer el capitan mac os x software#
I know that a lot of people are down on the Mac App Store, and some developers have even removed their software for one reason or another. Why I'm sticking with the Mac App Store for all of my software And it also eliminated all other software that had been installed from sources other than the Mac App Store (more on that below).
#Torrent site for installer el capitan mac os x install#
But I prefer to be safer than sorry, so a clean install of OS X El Capitan was an easy way to do that.

I had already deleted Transmission, despite the fact that I had apparently not been infected. I then did a clean install of OS X El Capitan to make extra sure that I would not have any problems. But just to be on the safe side, I grabbed my home folder and put it on an external drive to backup all of my data. I was fortunate in that I had updated to Transmission 2.90 via the in-app updater, not the Transmission site. But it was one of the better torrenting apps, so I liked having it handy in case I needed it. I've had Transmission on all of my Macs for ages, though I didn't use it very often. When I first heard about the Transmission ransomware in OS X, I did a bit of a double take. Palo Alto Networks has also updated URL filtering and Threat Prevention to stop KeRanger from impacting systems.Ī clean install of OS X El Capitan to purge software from third party sites Apple has since revoked the abused certificate and updated XProtect antivirus signature, and Transmission Project has removed the malicious installers from its website. Palo Alto Networks reported the ransomware issue to the Transmission Project and to Apple on March 4. Additionally, KeRanger appears to still be under active development and it seems the malware is also attempting to encrypt Time Machine backup files to prevent victims from recovering their back-up data. After completing the encryption process, KeRanger demands that victims pay one bitcoin (about $400) to a specific address to retrieve their files. The malware then begins encrypting certain types of document and data files on the system.

KeRanger then waits for for three days before connecting with command and control (C2) servers over the Tor anonymizer network. If a user installs the infected apps, an embedded executable file is run on the system.

The KeRanger application was signed with a valid Mac app development certificate therefore, it was able to bypass Apple’s Gatekeeper protection. It’s possible that Transmission’s official website was compromised and the files were replaced by re-compiled malicious versions, but we can’t confirm how this infection occurred. When we identified the issue, the infected DMG files were still available for downloading from the Transmission site () Transmission is an open source project. As FileCoder was incomplete at the time of its discovery, we believe KeRanger is the first fully functional ransomware seen on the OS X platform.Īttackers infected two installers of Transmission version 2.90 with KeRanger on the morning of March 4. We have named this Ransomware “KeRanger.” The only previous ransomware for OS X we are aware of is FileCoder, discovered by Kaspersky Lab in 2014. On March 4, we detected that the Transmission BitTorrent ailient installer for OS X was infected with ransomware, just a few hours after installers were initially posted.
