Transmission Malware Transmitted Through Server Hack, Downloaded 6,500 Times

Over the weekend, the first instance of Mac ransomware was found in a malicious update to the Transmission BitTorrent client. Version 2.90 of Transmission downloaded from the Transmission website was infected with "KeRanger" ransomware.

"Ransomware" is a class of malware that encrypts a user's hard drive and files, demanding money to decrypt it. In this case, KeRanger would have required Mac users to shell out a bitcoin for decryption, equivalent to approximately $400.

transmission-29
The developers behind Transmission have shared some additional details on the attack with Reuters, giving us some insight into how it occurred. The server that delivers the Transmission software to customers was breached in a cyber attack, allowing the KeRanger malware to be added to the disk-image of its software.

Transmission representative John Clay told Reuters via email that the ransomware was added to disk-image of its software after the project's server was compromised in a cyber attack.

"We're not commenting on the avenue of attack, other than to say that it was our main server that was compromised," he said. "The normal disk image (was) replaced by the compromised one."

During the time that the malware-infected version of Transmission was available, it was downloaded approximately 6,500 times before the vulnerability was discovered. Security on the server has since been increased, ensuring a similar attack can't occur a second time.

On Sunday, Transmission's developers released software updates to block the malicious software and to remove it from the Macs of users who had unwittingly installed the malicious version. Apple also updated its software protections to keep the malware from affecting Mac users and to prevent the bad version from being installed on additional machines.

Customers who have downloaded the Transmission BitTorrent client should make sure they have updated the software to version 2.92, which will remove the malware from infected computers. Additional details on how to determine if you have the malware installed are available through Palo Alto Networks.

Popular Stories

maxresdefault

Apple Shows Off a Key Reason to Upgrade to the iPhone 17

Saturday February 7, 2026 9:26 am PST by
Apple today shared an ad that shows how the upgraded Center Stage front camera on the latest iPhones improves the process of taking a group selfie. "Watch how the new front facing camera on iPhone 17 Pro takes group selfies that automatically expand and rotate as more people come into frame," says Apple. While the ad is focused on the iPhone 17 Pro and iPhone 17 Pro Max, the regular iPhone...
apple wallet drivers license feature iPhone 15 pro

Apple Says These 7 U.S. States Plan to Offer iPhone Driver's Licenses

Monday February 9, 2026 6:24 am PST by
In select U.S. states, residents can add their driver's license or state ID to the Apple Wallet app on the iPhone and Apple Watch, and then use it to display proof of identity or age at select airports and businesses, and in select apps. The feature is currently available in 13 U.S. states and Puerto Rico, and it is expected to launch in at least seven more in the future. To set up the...
m5 macbook pro deal

Why You Shouldn't Buy the Next MacBook Pro

Tuesday February 10, 2026 4:27 pm PST by
Apple is planning to launch new MacBook Pro models as soon as early March, but if you can, this is one generation you should skip because there's something much better in the works. We're waiting on 14-inch and 16-inch MacBook Pro models with M5 Pro and M5 Max chips, with few changes other than the processor upgrade. There won't be any tweaks to the design or the display, but later this...
iOS 26

Apple Releases iOS 26.3 and iPadOS 26.3

Wednesday February 11, 2026 10:07 am PST by
Apple today released iOS 26.3 and iPadOS 26.3, the latest updates to the iOS 26 and iPadOS 26 operating systems that came out in September. The new software comes almost two months after Apple released iOS 26.2 and iPadOS 26.2. The new software can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update. According to Apple's release notes, ...
Apple Logo Zoomed

Apple Expected to Launch These 10+ Products Over the Coming Months

Tuesday February 10, 2026 6:33 am PST by
It has been a slow start to 2026 for Apple product launches, with only a new AirTag and a special Apple Watch band released so far. We are still waiting for MacBook Pro models with M5 Pro and M5 Max chips, the iPhone 17e, a lower-cost MacBook with an iPhone chip, long-rumored updates to the Apple TV and HomePod mini, and much more. Apple is expected to release/update the following products...

Top Rated Comments

Junipr Avatar
130 months ago
I have zero sympathy for people who pirate stuff
Guessing the guys that think torrenting is strictly for piracy are the same guys that think an FBI backdoor gives us more freedom...
Score: 24 Votes (Like | Disagree)
benjitek Avatar
130 months ago
It'd be nice if the Transmission developers would explain how their site got compromised.

Still no word from them at all. We need a statement from them to show how this happened and the steps they are taking to prevent it from happening again, otherwise all trust in this developer is pretty much gone.
It's an open source project, and they're probably scrambling to get rid of it, figure out how it got there, before they make a public statement. First fix was a ransomware free version, and the 2nd included detection and removal of the ransomware. So far, that's pretty darn good ;)
Score: 7 Votes (Like | Disagree)
diddl14 Avatar
130 months ago
Guess this is why a restricted sandbox for each app is not such a bad idea...
Score: 7 Votes (Like | Disagree)
zorinlynx Avatar
130 months ago
It'd be nice if the Transmission developers would explain how their site got compromised.

Still no word from them at all. We need a statement from them to show how this happened and the steps they are taking to prevent it from happening again, otherwise all trust in this developer is pretty much gone.
Score: 7 Votes (Like | Disagree)
oneMadRssn Avatar
130 months ago
I like that the Transmission developers built-in a solution to the problem into the update, instead of just telling users to get an anti-virus to figure it out. This is good of them, and something that I don't ever see in the Windows world.
Score: 7 Votes (Like | Disagree)
TitoC Avatar
130 months ago
Torrenting is used overwhelming for pirating. I have zero sympathy for those that pirate.
First off - I have never been a fan of any torrent site or applications. I get all my files from legitimate sources and I pay for my music/videos.
I also have ZERO sympathy. But for people who know very little or who are completely oblivious to the real world use of torrenting and comment like they are in the "know" and lift their noses in disgust. I have several clients and collaborators who I constantly share very large files with. Many of my clients are game developers and video editors and they deal with large chunks of files that are much easier and quicker to download as a torrent as opposed to a large single file when collaborating.

Here are just a few examples of LEGAL everyday uses of torrenting:


* Blizzard Entertainment uses its own BitTorrent client to download World of Warcraft, Starcraft II, and Diablo III games. When you purchase one of these games and download it, you’re actually just downloading a BitTorrent client that will do the rest of the work.
* Facebook and Twitter Use BitTorrent Internally
* Many government agencies use torrent files.

While yes, most pirated items are shared and downloaded via torrent files, not all torrent files are used for pirating. That's like saying that most car thieves use coat hangers to break into cars so anyone who uses a coat hanger must be a thief. Please!
Score: 6 Votes (Like | Disagree)