TF-MAL-osx.macransom
📛 Threat Title
Malware family: MacRansom
Description
ThreatFox malware family `osx.macransom`. Printable name: MacRansom.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.macransom
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.macransom
IOC database
- Type
- domain
- Value
osx.macransom- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.macransom
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.macransom
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:argonsys.com
Malware creators deploy various anti-analysis techniques to evade or prevent the analysis of files by either analysts or automated analysis systems such as sandboxes. Among the Mac ransomware we studied, KeRanger, MacRansom , and EvilQuest employ hardware-based checks or use specific code apart from the usual obfuscation of strings to avoid ...
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.
-
web:learn.microsoft.com
Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.
-
web:undercodenews.com
🔮 Future Mirai-style malware families will likely incorporate multi-vulnerability exploitation chains targeting Four-Faith routers and similar industrial networking equipment simultaneously.
-
web:www.blackfog.com
MacRansom (2017): A lesser known but significant attack was MacRansom , a form of ransomware that encrypted files on Mac devices and displayed a ransom note demanding payment in Bitcoin. It was one of the first major indications that ransomware attacks could affect macOS users.
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.techrepublic.com
Microsoft uses four known ransomware families to explain the malware techniques on Mac: KeRanger, FileCoder, MacRansom and EvilQuest. Anti-analysis techniques used by MacRansom and EvilQuest
-
web:www.threatshub.org
Malware commonly uses persistence to ensure it runs even after a system restart. Among the Mac ransomware families analyzed, we've seen persistence techniques in EvilQuest and MacRansom .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.