logo

Creating macOS Ransomware

ID: 52d29ede-cd98-5e2f-bb5a-b93923a1047d

STIX ID: report--52d29ede-cd98-5e2f-bb5a-b93923a1047d

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2024-02-24

Date Updated: 2026-04-28

...
...

This Huntress write-up details discovering a defective macOS ransomware script, the fixes applied to make it operational, and a breakdown of the final payload: generating a random password, creating an encrypted APFS volume, relocating and unmounting target files into that volume, and securely exfiltrating the decryption key via OpenSSL; the article frames the exercise as offensive testing to improve defensive tradecraft and notes the script worked on macOS Monterey.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.