Creating macOS Ransomware
ID: 52d29ede-cd98-5e2f-bb5a-b93923a1047d
STIX ID: report--52d29ede-cd98-5e2f-bb5a-b93923a1047d
Feed Name: Huntress Blog
Threat Score
This Huntress write-up details discovering a defective macOS ransomware script, the fixes applied to make it operational, and a breakdown of the final payload: generating a random password, creating an encrypted APFS volume, relocating and unmounting target files into that volume, and securely exfiltrating the decryption key via OpenSSL; the article frames the exercise as offensive testing to improve defensive tradecraft and notes the script worked on macOS Monterey.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
