Transmission Malware Transmitted Through Server Hack, Downloaded 6,500 Times

Over the weekend, the first instance of Mac ransomware was found in a malicious update to the Transmission BitTorrent client. Version 2.90 of Transmission downloaded from the Transmission website was infected with "KeRanger" ransomware.

"Ransomware" is a class of malware that encrypts a user's hard drive and files, demanding money to decrypt it. In this case, KeRanger would have required Mac users to shell out a bitcoin for decryption, equivalent to approximately $400.

transmission-29
The developers behind Transmission have shared some additional details on the attack with Reuters, giving us some insight into how it occurred. The server that delivers the Transmission software to customers was breached in a cyber attack, allowing the KeRanger malware to be added to the disk-image of its software.

Transmission representative John Clay told Reuters via email that the ransomware was added to disk-image of its software after the project's server was compromised in a cyber attack.

"We're not commenting on the avenue of attack, other than to say that it was our main server that was compromised," he said. "The normal disk image (was) replaced by the compromised one."

During the time that the malware-infected version of Transmission was available, it was downloaded approximately 6,500 times before the vulnerability was discovered. Security on the server has since been increased, ensuring a similar attack can't occur a second time.

On Sunday, Transmission's developers released software updates to block the malicious software and to remove it from the Macs of users who had unwittingly installed the malicious version. Apple also updated its software protections to keep the malware from affecting Mac users and to prevent the bad version from being installed on additional machines.

Customers who have downloaded the Transmission BitTorrent client should make sure they have updated the software to version 2.92, which will remove the malware from infected computers. Additional details on how to determine if you have the malware installed are available through Palo Alto Networks.

Top Rated Comments

Junipr Avatar
74 months ago
I have zero sympathy for people who pirate stuff
Guessing the guys that think torrenting is strictly for piracy are the same guys that think an FBI backdoor gives us more freedom...
Score: 24 Votes (Like | Disagree)
benjitek Avatar
74 months ago
It'd be nice if the Transmission developers would explain how their site got compromised.

Still no word from them at all. We need a statement from them to show how this happened and the steps they are taking to prevent it from happening again, otherwise all trust in this developer is pretty much gone.
It's an open source project, and they're probably scrambling to get rid of it, figure out how it got there, before they make a public statement. First fix was a ransomware free version, and the 2nd included detection and removal of the ransomware. So far, that's pretty darn good ;)
Score: 7 Votes (Like | Disagree)
diddl14 Avatar
74 months ago
Guess this is why a restricted sandbox for each app is not such a bad idea...
Score: 7 Votes (Like | Disagree)
zorinlynx Avatar
74 months ago
It'd be nice if the Transmission developers would explain how their site got compromised.

Still no word from them at all. We need a statement from them to show how this happened and the steps they are taking to prevent it from happening again, otherwise all trust in this developer is pretty much gone.
Score: 7 Votes (Like | Disagree)
oneMadRssn Avatar
74 months ago
I like that the Transmission developers built-in a solution to the problem into the update, instead of just telling users to get an anti-virus to figure it out. This is good of them, and something that I don't ever see in the Windows world.
Score: 7 Votes (Like | Disagree)
TitoC Avatar
74 months ago
Torrenting is used overwhelming for pirating. I have zero sympathy for those that pirate.
First off - I have never been a fan of any torrent site or applications. I get all my files from legitimate sources and I pay for my music/videos.
I also have ZERO sympathy. But for people who know very little or who are completely oblivious to the real world use of torrenting and comment like they are in the "know" and lift their noses in disgust. I have several clients and collaborators who I constantly share very large files with. Many of my clients are game developers and video editors and they deal with large chunks of files that are much easier and quicker to download as a torrent as opposed to a large single file when collaborating.

Here are just a few examples of LEGAL everyday uses of torrenting:


* Blizzard Entertainment uses its own BitTorrent client to download World of Warcraft, Starcraft II, and Diablo III games. When you purchase one of these games and download it, you’re actually just downloading a BitTorrent client that will do the rest of the work.
* Facebook and Twitter Use BitTorrent Internally
* Many government agencies use torrent files.

While yes, most pirated items are shared and downloaded via torrent files, not all torrent files are used for pirating. That's like saying that most car thieves use coat hangers to break into cars so anyone who uses a coat hanger must be a thief. Please!
Score: 6 Votes (Like | Disagree)

Related Stories

studio buds family

Beats Studio Buds Debuting Today With Active Noise Cancellation, Stemless Design, and More for $150

Monday June 14, 2021 8:00 am PDT by
We've seen a lot of teasers about the Beats Studio Buds over the past month since they first showed up in Apple's beta software updates, and today they're finally official. The Beats Studio Buds are available to order today in red, white, and black ahead of a June 24 ship date, and they're priced at $149.99. The Studio Buds are the first Beats-branded earbuds to truly compete with AirPods...
macos catalina legacy system extension alert

Apple Begins Warning Users That 'Legacy System Extensions' Won't Work With a Future Version of macOS

Wednesday March 25, 2020 9:53 am PDT by
Apple has shared a new support document that indicates kernel extensions — which it calls "legacy system extensions" — will not be compatible with a future version of macOS because they "aren't as secure or reliable as modern alternatives."System extensions are a category of software that works in the background to extend the functionality of your Mac. Some apps install kernel extensions, which...
General Spotify Feature

Spotify Pauses Plans to Add AirPlay 2 Support to iOS App [Update: Spotify Clarifies]

Friday August 6, 2021 9:07 am PDT by
See update at bottom of article Spotify this week confirmed that its plans to add AirPlay 2 support to its iOS app have been placed on indefinite hiatus. In an online discussion forum post, a Spotify representative said the streaming music service had been working on supporting AirPlay 2, but the company has paused the efforts "for now" due to "audio driver compatibility issues." The...
apple privacy

Apple Publishes FAQ to Address Concerns About CSAM Detection and Messages Scanning

Monday August 9, 2021 1:50 am PDT by
Apple has published a FAQ titled "Expanded Protections for Children" which aims to allay users' privacy concerns about the new CSAM detection in iCloud Photos and communication safety for Messages features that the company announced last week. "Since we announced these features, many stakeholders including privacy organizations and child safety organizations have expressed their support of...
youtube apple tv

YouTube Discontinuing 3rd-Generation Apple TV App, AirPlay Still Available

Wednesday February 3, 2021 3:09 pm PST by
YouTube is planning to stop supporting its YouTube app on the third-generation Apple TV models, where YouTube has long been available as a channel option. A 9to5Mac reader received a message about the upcoming app discontinuation, which is set to take place in March.Starting early March, the YouTube app will no longer be available on Apple TV (3rd generation). You can still watch YouTube on...
m1 macbook air

Kuo: Mini-LED MacBook Air Coming in Mid-2022

Thursday July 22, 2021 7:48 pm PDT by
Apple will release a new version of the MacBook Air around the middle of 2022, Apple analyst Ming-Chi Kuo said today in note to investors seen by MacRumors. The upcoming MacBook Air will feature a 13.3-inch mini-LED display, which would make it the second Mac to gain mini-LED technology after the 2021 MacBook Pro, which is rumored to include a mini-LED display and is expected to launch later ...
Apple Films Tom Hanks Finch First Look

Apple Original Film 'Finch' Starring Tom Hanks to Premiere November 5

Thursday August 12, 2021 8:52 am PDT by
Apple today announced that the original film "Finch," starring Tom Hanks in its titular role, will premiere on Apple TV+ on Friday, November 5 and shared a first-look image from the film. The first look at "Finch," shared by Apple. The film, which is anticipated to be an awards season contender, revolves around a man, a robot (played by "Get Out" actor Caleb Landry Jones), and a dog that form ...
whatsintheboxiphonexs

Apple's iPhone XS, XS Max and XR Won't Ship With Lightning to 3.5mm Headphone Jack Adapter

Wednesday September 12, 2018 12:58 pm PDT by
Since the headphone jack was removed from the iPhone with the launch of the iPhone 7, Apple has bundled iPhones with a Lightning to 3.5mm Headphone Jack Adapter for customers who continue to have 3.5mm headphones. With the launch of the iPhone XS, iPhone XS Max, and iPhone XR, Apple is discontinuing this practice and will not include the Lightning to 3.5mm Headphone Jack Adapter. On the...
macbook air m1 first benchmark

Apple Silicon M1 Chip in MacBook Air Outperforms High-End 16-Inch MacBook Pro

Wednesday November 11, 2020 4:43 pm PST by
Apple introduced the first MacBook Air, MacBook Pro, and Mac mini with M1 Apple Silicon chips yesterday, and as of today, the first benchmark of the new chip appears to be showing up on the Geekbench site. The M1 chip, which belongs to a MacBook Air with 8GB RAM, features a single-core score of 1687 and a multi-core score of 7433. According to the benchmark, the M1 has a 3.2GHz base...
iphone 13 teal with text

Apple Begins Preparation for iPhone 13 Production Ahead of Fall Launch

Monday June 28, 2021 3:29 am PDT by
We're just a few months away from when Apple is expected to reveal the 2021 iPhone, dubbed the "iPhone 13." In preparation for its launch, it has been pulling in shipments of different components needed to produce the new iPhones, according to a report from DigiTimes. In years past, Apple released its latest iPhone lineup, alongside a new Apple Watch, during a September event at Apple Park....