Ransomware intended for Macs is cause for concern, not panic

For the first time, a prominent ransomware group appears to be actively targeting macOS computers. Discovered last weekend by MalwareHunterTeam, the code sample suggests that the Russia-based LockBit gang is working on a version of its malware that would encrypt files on Mac devices.

Small businesses, large enterprises, and government institutions are frequently the target of ransomware attacks. Hackers often use phishing emails to send real-seeming messages to try to trick staff into downloading the ransomware payload. Once it’s in, the malware spreads around any computer systems, automatically encrypting user files and preventing the organization from operating until a ransom is paid—usually in crypto currencies like Bitcoin. 

Over the past few years, ransomware attacks have disrupted fuel pipelines, schools, hospitals, cloud providers, and countless other businesses. LockBit has been responsible for hundreds of these attacks, and in the past six months has brought down the UK’s Royal Mail international shipping service and disrupted operations in a Canadian children’s hospital over the Christmas period.

Up until now, these ransomware attacks mostly targeted Windows, Linux, and other enterprise operating systems. While Apple computers are popular with consumers, they aren’t as commonly used in the kind of businesses and other deep-pocketed organizations that ransomware gangs typically go after. 

MalwareHunterTeam, an independent group of security researchers, only discovered the Mac encryptors recently, but they have apparently been present on malware-tracking site VirusTotal since November last year. One encryptor targets Apple Macs with the newer M1 chips, while another targets those with Power PC CPUs, which were all developed before 2006. Presumably, there is a third encryptor somewhere that targets Intel-based Macs, although it doesn’t appear to be in the VirusTotal repository. 

Fortunately, when BleepingComputer assessed the Apple M1 encryptor, it found a fairly half-baked bit of malware. There were lots of code fragments that they said “are out of place in a macOS encryptor.” It concluded that the encryptor was “likely haphazardly thrown together in a test.”

In a deep dive into the M1 encryptor, security researcher Patrick Wardle discovered much the same thing. He found that the code was incomplete, buggy, and missing the features necessary to actually encrypt files on a Mac. In fact, since it wasn’t signed with an Apple Developer ID, it wouldn’t even run in its present state. According to Wardle, “the average macOS user is unlikely to be impacted by this LockBit macOS sample” but that a “large ransomware gang has apparently set its sights on macOS, should give us pause for concern and also catalyze conversions about detecting and preventing this (and future) samples in the first place!”

Apple has also preemptively implemented a number of security features that mitigate the risks from ransomware attacks. According to Wardle, operating system-level files are protected by both System Integrity Protection and read-only system volumes. This makes it hard for ransomware to do much to disrupt how macOS works even if it does end up on your computer. Similarly, Apple protects directories such as the Desktop, Documents, and other folders, so the ransomware wouldn’t be able to encrypt them without user approval or an exploit. This doesn’t mean it’s impossible that ransomware could work on a Mac, but it certainly won’t be easy on those that are kept up-to-date with the latest security features. 

Still, the fact that a large hacking group is seemingly targeting Macs is still a big deal—and it’s a reminder that whatever reputation Apple has for developing more secure devices is constantly being put to the test. When BleepingComputer contacted LockBitSupp, the public face of LockBit, the group confirmed that a Mac encryptor is “actively being developed.” While the ransomware won’t do much in its present state, you should always keep your Mac up-to-date—and be careful with any suspicious files you download from the internet.

Read More
Harry Guinness

Latest

I Drove Hyundai’s Hydrogen-Fueled Nexo. It’s Perfect, Just Not for the US

Hyundai's new 2026 Nexo is an electric SUV that cruises for up to 450 miles and refuels at a familiar-looking pump in 5 minutes. Instead of a battery pack, the Nexo generates electricity on the go from a hydrogen tank and fuel cell. On paper, it's exactly what Americans want -- long-range, fast fill-ups, few

10 Years Later, One of The Best Shonen Jump Series of All Time Is Still Awaiting a Sequel

Written and illustrated by Katsura Hoshino, D.Gray-man is one of the best series ever published in the Weekly Shonen Jump magazine. While the manga began serialization in 2004, it faced multiple hiatuses due to the creator’s poor health and never got the attention it deserved. In April 2018, the series moved to the quarterly magazine Jump SQ.

Exodus’ former studio head James Ohlen touches on why he left Archetype Entertainment: “I was running on fumes”

"It was hurting my health" Image credit: Archetype Entertainment Back in December of last year, despite being the head of the studio, James Ohlen left Archetype Entertainment, also leaving his role as producer on Exodus behind. It was a bit of a surprise, given that he co-founded the studio after having retired from BioWare in

“We will probably get some flack”: Subnautica 2 may feel polished for an early access game, but it was important for the team it...

No one wants another Moonbreaker Image credit: Krafton / Rock Paper Shotgun It's been more than a decade since the original Subnautica dove into early access. The deep sea survival game spent four years there as developer Unknown Worlds Entertainment added new features, biomes, and polished the whole thing up with the game's players. It

Newsletter

Don't miss

I Drove Hyundai’s Hydrogen-Fueled Nexo. It’s Perfect, Just Not for the US

Hyundai's new 2026 Nexo is an electric SUV that cruises for up to 450 miles and refuels at a familiar-looking pump in 5 minutes. Instead of a battery pack, the Nexo generates electricity on the go from a hydrogen tank and fuel cell. On paper, it's exactly what Americans want -- long-range, fast fill-ups, few

10 Years Later, One of The Best Shonen Jump Series of All Time Is Still Awaiting a Sequel

Written and illustrated by Katsura Hoshino, D.Gray-man is one of the best series ever published in the Weekly Shonen Jump magazine. While the manga began serialization in 2004, it faced multiple hiatuses due to the creator’s poor health and never got the attention it deserved. In April 2018, the series moved to the quarterly magazine Jump SQ.

Exodus’ former studio head James Ohlen touches on why he left Archetype Entertainment: “I was running on fumes”

"It was hurting my health" Image credit: Archetype Entertainment Back in December of last year, despite being the head of the studio, James Ohlen left Archetype Entertainment, also leaving his role as producer on Exodus behind. It was a bit of a surprise, given that he co-founded the studio after having retired from BioWare in

“We will probably get some flack”: Subnautica 2 may feel polished for an early access game, but it was important for the team it...

No one wants another Moonbreaker Image credit: Krafton / Rock Paper Shotgun It's been more than a decade since the original Subnautica dove into early access. The deep sea survival game spent four years there as developer Unknown Worlds Entertainment added new features, biomes, and polished the whole thing up with the game's players. It

UK games industry fundamentally misunderstood, new report calls for unified research framework

UKIE and entertainment charity OKRE call for industry, government, and academia to collaborate on the framework to address identified research gaps Image credit: James Newcombe UKIE and entertainment charity OKRE have developed a framework to help the UK games industry maximise its economic and social value. The Building a Unified Framework for the UK Video

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand

Getting a business loan now comes with a frequent flyer upside

Australian fintech Prospa has partnered with Qantas Business Rewards, letting eligible SMEs earn up to 500,000 points per loan. What’s happening: Australian fintech lender Prospa has partnered with Qantas Business Rewards to allow eligible small and medium business owners to earn up to 500,000 Qantas Points per loan when taking out a Prospa Small Business