Transmission Malware Transmitted Through Server Hack, Downloaded 6,500 Times

Over the weekend, the first instance of Mac ransomware was found in a malicious update to the Transmission BitTorrent client. Version 2.90 of Transmission downloaded from the Transmission website was infected with "KeRanger" ransomware.

"Ransomware" is a class of malware that encrypts a user's hard drive and files, demanding money to decrypt it. In this case, KeRanger would have required Mac users to shell out a bitcoin for decryption, equivalent to approximately $400.

transmission-29
The developers behind Transmission have shared some additional details on the attack with Reuters, giving us some insight into how it occurred. The server that delivers the Transmission software to customers was breached in a cyber attack, allowing the KeRanger malware to be added to the disk-image of its software.

Transmission representative John Clay told Reuters via email that the ransomware was added to disk-image of its software after the project's server was compromised in a cyber attack.

"We're not commenting on the avenue of attack, other than to say that it was our main server that was compromised," he said. "The normal disk image (was) replaced by the compromised one."

During the time that the malware-infected version of Transmission was available, it was downloaded approximately 6,500 times before the vulnerability was discovered. Security on the server has since been increased, ensuring a similar attack can't occur a second time.

On Sunday, Transmission's developers released software updates to block the malicious software and to remove it from the Macs of users who had unwittingly installed the malicious version. Apple also updated its software protections to keep the malware from affecting Mac users and to prevent the bad version from being installed on additional machines.

Customers who have downloaded the Transmission BitTorrent client should make sure they have updated the software to version 2.92, which will remove the malware from infected computers. Additional details on how to determine if you have the malware installed are available through Palo Alto Networks.

Popular Stories

iOS 26 Battery Glass Feature

iPhone 16 Pro Max 80% Charge Limit: One Year Later, Was It Worth It?

Wednesday September 24, 2025 3:58 pm PDT by
With the iPhone 15 series, I did an experiment and kept my iPhone's Charge Limit set at 80 percent for an entire year. It provided an interesting look at the impact of charge limits on battery longevity, so I decided to repeat it for the iPhone 16 line. Since September 2024, my iPhone 16 Pro Max has been limited to an 80 percent charge, with no cheating. As of today, my battery's maximum...
iOS 26

Everything New in iOS 26.1 Beta 1

Monday September 22, 2025 12:44 pm PDT by
Apple released the first beta of iOS 26.1 today, just a week after launching iOS 26. iOS 26.1 mainly adds new languages to Apple Intelligence, but there are a few other features that are worth knowing about. New Apple Intelligence Languages Apple Intelligence is now available in Danish, Dutch, Norwegian, Portuguese (Portugal), Swedish, Turkish, Chinese (Traditional), and Vietnamese. AirPo...
iPhone 17 Pro Colors

Skipped the iPhone 17 Pro? Here's What is Rumored for iPhone 18 Pro

Tuesday September 23, 2025 8:55 am PDT by
While the iPhone 18 Pro and iPhone 18 Pro Max are still a year away, there are already a few rumors about the devices that offer an early look ahead. Below, we have recapped some of the early iPhone 18 Pro rumors so far. This story was published previously, and it has been updated to reflect the latest rumors. Many early rumors prove to be true, but nothing is confirmed yet, and Apple's...
apple tv 4k new orange

Next Apple TV Expected to Launch This Year With These New Features

Monday September 22, 2025 10:00 am PDT by
The next Apple TV is expected to be released later this year, and a handful of new features and changes have been rumored for the device. Below, we recap what to expect from the next Apple TV, according to rumors. Likely Features N1 Chip With Wi-Fi 7 Last year, Bloomberg's Mark Gurman said the next Apple TV would be equipped with Apple's own combined Wi-Fi and Bluetooth chip, which is...
iPhone 17 Pro USB C Port

iPhone 17 Pro Max's USB-C Charging Speeds Tested With Apple Chargers

Monday September 22, 2025 7:29 am PDT by
The website ChargerLAB has tested the iPhone 17 Pro Max's USB-C charging speeds with a variety of Apple's chargers, from 18W to 140W. The device reached a peak charging speed of around 36W with the following Apple chargers:40W Dynamic Power Adapter with 60W Max 61W USB-C Power Adapter 67W USB-C Power Adapter 70W USB-C Power Adapter 96W USB-C Power Adapter 140W USB-C Power AdapterFor...
iphone 17 pro dark blue 1

Apple Blames In-Store MagSafe Chargers for iPhone 17 Pro Display Model Scratches

Wednesday September 24, 2025 10:22 am PDT by
The marks on the iPhone 17 Pro models that people have noticed at Apple retail stores are caused by the chargers that Apple uses, Apple confirmed today. Apple told 9to5Mac that worn MagSafe charging stands in stores are causing marks on the iPhone 17 Pro and iPhone 17 Pro Max. Apple says that the marks are not scratches, and are instead material transfer from the stand to the phone. The...
AirPods Pro 3 Newsroom

Apple's 'Back to School' Offer Ends Soon, Now Applies to AirPods Pro 3

Wednesday September 24, 2025 7:20 am PDT by
Apple's annual "Back to School" promotion for students ends soon, so act fast if you want to score free AirPods with the purchase of an eligible new Mac or iPad. Until Tuesday, September 30, college students and qualifying educational staff in the U.S. can receive free AirPods 4 with Active Noise Cancellation when they purchase an eligible new Mac or iPad from Apple. This is a $179 value. ...
ios 26 digital id passport wallet

Apple Confirms iOS 26 Wallet Passport Feature is Coming in 2025

Tuesday September 23, 2025 1:06 pm PDT by
Digital ID, the iOS 26 feature that lets U.S. passport holders add their passports to the Wallet app, is coming later in 2025, Apple confirmed today. Apple updated the release timing wording of Digital ID on its iOS 26 features page. "Digital ID will be coming later this year with US passports only," it reads. Prior to today, the footnote for the feature said "Digital ID will be available ...
Apple Intelligence General Feature 2

iOS 26.1 Adds New Apple Intelligence Languages and Expands AirPods Live Translation

Monday September 22, 2025 11:15 am PDT by
With iOS 26.1, Apple Intelligence is gaining support for additional languages, including Danish, Dutch, Norwegian, Portuguese (Portugal), Swedish, Turkish, Chinese (Traditional), and Vietnamese. Apple announced plans to expand the languages that can be used with Apple Intelligence last year, and now the added language support is here. Apple Intelligence is now available in the following...
maxresdefault

iPhone 17 Pro is Vulnerable to Scratching, But Not Where You Might Think

Tuesday September 23, 2025 2:18 pm PDT by
Early reports have suggested that the iPhone 17 Pro and iPhone Air are more vulnerable to scratches and scuffs, primarily due to damage spotted at Apple Stores. Apple customers have discovered that the iPhone Air and iPhone 17 Pro models Apple has out for display at its retail locations have scratching in the area of the MagSafe charger. Those devices are handled by hundreds to thousands of...

Top Rated Comments

Junipr Avatar
125 months ago
I have zero sympathy for people who pirate stuff
Guessing the guys that think torrenting is strictly for piracy are the same guys that think an FBI backdoor gives us more freedom...
Score: 24 Votes (Like | Disagree)
benjitek Avatar
125 months ago
It'd be nice if the Transmission developers would explain how their site got compromised.

Still no word from them at all. We need a statement from them to show how this happened and the steps they are taking to prevent it from happening again, otherwise all trust in this developer is pretty much gone.
It's an open source project, and they're probably scrambling to get rid of it, figure out how it got there, before they make a public statement. First fix was a ransomware free version, and the 2nd included detection and removal of the ransomware. So far, that's pretty darn good ;)
Score: 7 Votes (Like | Disagree)
diddl14 Avatar
125 months ago
Guess this is why a restricted sandbox for each app is not such a bad idea...
Score: 7 Votes (Like | Disagree)
zorinlynx Avatar
125 months ago
It'd be nice if the Transmission developers would explain how their site got compromised.

Still no word from them at all. We need a statement from them to show how this happened and the steps they are taking to prevent it from happening again, otherwise all trust in this developer is pretty much gone.
Score: 7 Votes (Like | Disagree)
oneMadRssn Avatar
125 months ago
I like that the Transmission developers built-in a solution to the problem into the update, instead of just telling users to get an anti-virus to figure it out. This is good of them, and something that I don't ever see in the Windows world.
Score: 7 Votes (Like | Disagree)
TitoC Avatar
125 months ago
Torrenting is used overwhelming for pirating. I have zero sympathy for those that pirate.
First off - I have never been a fan of any torrent site or applications. I get all my files from legitimate sources and I pay for my music/videos.
I also have ZERO sympathy. But for people who know very little or who are completely oblivious to the real world use of torrenting and comment like they are in the "know" and lift their noses in disgust. I have several clients and collaborators who I constantly share very large files with. Many of my clients are game developers and video editors and they deal with large chunks of files that are much easier and quicker to download as a torrent as opposed to a large single file when collaborating.

Here are just a few examples of LEGAL everyday uses of torrenting:


* Blizzard Entertainment uses its own BitTorrent client to download World of Warcraft, Starcraft II, and Diablo III games. When you purchase one of these games and download it, you’re actually just downloading a BitTorrent client that will do the rest of the work.
* Facebook and Twitter Use BitTorrent Internally
* Many government agencies use torrent files.

While yes, most pirated items are shared and downloaded via torrent files, not all torrent files are used for pirating. That's like saying that most car thieves use coat hangers to break into cars so anyone who uses a coat hanger must be a thief. Please!
Score: 6 Votes (Like | Disagree)