Breaking
December 15, 2024

NotLockBit ransomware targets Apple users with advanced file-locking and data exfiltration udinmwenefosa@gmail.com (Efosa Udinmwen) | usagoldmines.com

  • macOS faces an emerging ransomware threat, NotLockBit
  • NotLockBit malware demonstrates file-locking capabilities
  • Apple’s built-in protections face issues from evolving ransomware threats

For years, ransomware attacks have predominantly targeted Windows and Linux platforms, however cybercriminals have begun to shift their focus toward macOS users, experts have claimed.

The recent discovery of macOS.NotLockBit suggests a shift in the landscape, as this newly identified malware, named after the notorious LockBit variant, could mark the beginning of more serious ransomware campaigns against Mac users.

Discovered by researchers at Trend Micro and later analyzed by SentinelLabs, macOS.NotLockBit shows credible file-locking and data exfiltration capabilities, posing a potential risk to macOS users.

macOS.NotLockBit threat

Ransomware targeting Mac devices tends to lack the necessary tools to truly lock files or exfiltrate data. The general perception has been that macOS is better protected against these kinds of threats, partially due to Apple’s built-in security features, such as Transparency, Consent, and Control (TCC) protections. However, the emergence of macOS.NotLockBit signals that hackers are actively developing more sophisticated methods for targeting Apple devices.

macOS.NotLockBit functions similarly to other ransomware, but it specifically targets macOS systems. The malware only runs on Intel-based Macs or Apple silicon Macs with Rosetta emulation software installed, which allows it to execute x86_64 binaries on newer Apple processors.

Upon execution, the ransomware collects system information, including the product name, version, and architecture. It also gathers data on how long the system has been running since its last reboot. Before locking the user’s files, macOS.NotLockBit attempts to exfiltrate data to a remote server using Amazon Web Services (AWS) S3 storage. The malware employs a public key for asymmetric encryption, meaning decryption without the attacker’s private key is nearly impossible.

The malware drops a README.txt file in directories containing encrypted files. The encrypted files are marked with an “.abcd” extension, and the README instructs victims on how to recover their files, typically by paying a ransom. Additionally, in later versions of the malware, macOS.NotLockBit displays a LockBit 2.0-themed desktop wallpaper, co-opting the branding of the LockBit ransomware group.

Thankfully, Apple’s TCC protections remain a hard nut for macOS.NotLockBit to crack. These safeguards require user consent before granting access to sensitive directories or allowing control over processes like System Events. While this creates a hurdle for the ransomware’s full functionality, bypassing TCC protection is not insurmountable, and security experts expect that future iterations of the malware may develop ways to circumvent these alerts.

Researchers from SentinelLabs and Trend Micro have not yet identified a specific distribution method, and there are no known victims at present. However, the rapid evolution of the malware demonstrated by the increasing size and sophistication of each new sample indicates that the attackers are actively working on improving its capabilities.

SentinelLabs identified multiple versions of the malware, suggesting that macOS.NotLockBit is still in active development. Early samples appeared lighter in functionality, focusing solely on encryption. Later versions added data exfiltration capabilities and began employing AWS S3 cloud storage to exfiltrate stolen files. The attackers hardcoded AWS credentials into the malware to create new repositories for storing victim data, though these accounts have since been deactivated.

In one of its most recent versions, macOS.NotLockBit requires macOS Sonoma, indicating that the malware developers are targeting some the latest macOS versions. It also showed attempts at obfuscating code, suggesting that the attackers are testing various techniques to evade detection by antivirus software.

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Microsoft 365 fees adding up? Get a permanent Office license for cheap | usagoldmines.com
Master the art of AI and make automation your new superpower | usagoldmines.com
AI investment isn't slowing down — venture capitalists are funding startups while trying to grapple ...
NYT Strands today — my hints, answers and spangram for Sunday, December 15 (game #287) | usagoldmin...
Quordle today – my hints and answers for Sunday, December 15 (game #1056) | usagoldmines.com
NYT Connections today — my hints and answers for Sunday, December 15 (game #553) | usagoldmines.com
US border surveillance towers face significant operational failures — vast areas unwatched, national...
Hey sysadmin, this is the perfect Christmas laptop gift for you; HX 370-powered Pocket 4 has a RS232...
Chinese flagship phones are great value for money, but they won't stay cheaper for much longer – her...
Rivian Gets Google Cast, YouTube App in Holiday Update Kellen | usagoldmines.com
The Samsung Galaxy S25 Ultra could come with a stylish new color | usagoldmines.com
Galaxy Watch Ultra Gets $460 Off Deal, But You Get a Bonus Free $80 Band Too Kellen | usagoldmines.c...
UGREEN Takes Up to 40% Off Uno Chargers and More in Amazon Sale Mitchel Broussard | usagoldmines.com
US government to restrict investments in China's high-tech sectors to safeguard national security ud...
Galaxy S24 Ultra Keeps Sitting at $800 Off With Trades Kellen | usagoldmines.com
Top Stories: iOS 18.2 Out Now, iPhone and Mac Rumors, and More MacRumors Staff | usagoldmines.com
The new Vault Hunter designs in Borderlands 4 are fine actually, you’re all just being mean christia...
Apple rumored to have started production on the iPhone 17 Air | usagoldmines.com
The US wants security requirements as standard to stop sensitive data from falling into enemy hands ...
EU citizens are enthusiastic about AI use in law enforcement, but some fear it is a danger to democr...
iMac Pro Launched Seven Years Ago Today Hartley Charlton | usagoldmines.com
Samsung Galaxy S25 rumored features: the key tipped upgrades on the S25 line | usagoldmines.com
Hugging Face launches an open source tool for affordable AI deployment udinmwenefosa@gmail.com (Efos...
The easiest way to get a $45 Costco Digital Shop Card | usagoldmines.com
ICYMI: the week's 7 biggest tech stories from Samsung's XR headset reveal to Apple's 17 favorite App...
Paramount Plus: how to watch, price, free trial, movies, TV shows, and more tom.power@futurenet.com ...
The Bose New Soundlink Flex Is Down to Its Lowest Price (and It Arrives Before Christmas) Daniel Oro...
11 of the Best Music Documentaries Ever Made Jason Keil | usagoldmines.com
Four Situations When Supplemental Health Insurance Makes Sense (When You’re Not Retired) Jeff Somers...
All The Biggest Reveals From the 2024 Game Awards Michelle Ehrhardt | usagoldmines.com
iOS 18.2: What You Can Do With Visual Intelligence Juli Clover | usagoldmines.com
Character.AI won't let its chatbots get romantic with teenagers anymore erichs211@gmail.com (Eric Ha...
NYT Strands today — my hints, answers and spangram for Saturday, December 14 (game #286) | usagoldm...
NYT Connections today — my hints and answers for Saturday, December 14 (game #552) | usagoldmines.c...
Quordle today – my hints and answers for Saturday, December 14 (game #1055) | usagoldmines.com
The Best Ways to Find a Running Track Near You (and a Beginner’s Workout to Try) Beth Skwarecki | us...
What You Can and Can't Make With iOS 18.2's Genmoji Feature Juli Clover | usagoldmines.com
Malcolm, Malcolm, Malcolm! Yes, 'Malcolm in the Middle' is being revived for Disney Plus jacob.krol@...
Amazon teams up with Samsung rival to design and build bespoke next generation tech that will help A...
The Intel Arc B580 GPU could rejuvenate the budget PC market - here's why allisa.james@futurenet.com...
Bird flu jumps from birds to human in Louisiana; patient hospitalized Beth Mole | usagoldmines.com
My Best Advice for Shipping Holiday Cookies Without Ruining Them Allie Chanthorn Reinmann | usagoldm...
ChatGPT Can Finally See Jake Peterson | usagoldmines.com
Yearlong supply-chain attack targeting security pros steals 390K credentials Dan Goodin | usagoldmin...
Windows PCs are full of ads. These 9 settings turn off the worst ones | usagoldmines.com
5 useful PC upgrades to plug into your unused PCIe slots | usagoldmines.com
Best Windows backup software 2024: Protect your data! | usagoldmines.com
Best gaming laptops under $1,000: Expert picks that won’t break the bank | usagoldmines.com
Classic Outlook gets an official ‘death date’ as users are urged to switch | usagoldmines.com
Best VPNs for Android 2024: Our picks for phones and tablets | usagoldmines.com
Mint Mobile Cuts $400 Off Pixel 9 Pro, Gives You Unlimited for 12 Months at 50% Off Kellen | usagold...
You Can Max Out Your IRA Contributions for Longer Than You Might Think Emily Long | usagoldmines.com
iOS 18.2: Here's How Mail Categories Work Juli Clover | usagoldmines.com
ChatGPT's new Projects feature can organize your AI clutter erichs211@gmail.com (Eric Hal Schwartz) ...
December Pixel Update Expands to Pixel Fold, Pixel 7 on T-Mobile Kellen | usagoldmines.com
WhatsApp Now Lets You Call Select Members of a Group Chat Jake Peterson | usagoldmines.com
Toxic Christmas Tree Water and Other Holiday Pet Dangers You Never Knew About Lindsey Ellefson | usa...
Best laptops for college students 2024: Top picks and expert advice | usagoldmines.com
It’s Time to Learn What ‘Core Sleep’ Actually Is Beth Skwarecki | usagoldmines.com
Report: Apple to Stop Selling iPhone 14 and iPhone SE in EU This Month Joe Rossignol | usagoldmines....
Best Apple Deals of the Week: Steep Discounts Hit Apple Watches and Bands, Plus Sales on AirTag, Ank...
“6G can efficiently enable intelligent computing everywhere”: Qualcomm offers an exclusive sneak pee...
Hackers are abusing Microsoft tools more than ever before | usagoldmines.com
Microsoft announced Phi-4, a new AI that’s better at math and language processing | usagoldmines.co...
Google Home Devices Get First Taste of Gemini in Place of Assistant Kellen | usagoldmines.com
This iPhone 15 Pro Max Is Less Than $900 Pradershika Sharma | usagoldmines.com
Google Maps’ Best Feature Is About to Get a Lot Less Useful David Nield | usagoldmines.com
Apple Begins Selling New Vision Pro Carry Sling and Exclusive Charging Accessories Juli Clover | usa...
I didn’t expect Fallout to win Best Adaptation at The Game Awards 2024 when Netflix’s Arcane was suc...
This Yoto Mini 'fire hazard' children's speaker has been recalled again due to its overheating batte...
Werner Herzog muses on mysteries of the brain in Theater of Thought Jennifer Ouellette | usagoldmine...
Nvidia stokes RTX 50-series hype with Witcher 4 and a global LAN party | usagoldmines.com
Google’s Pixel Camera Update Returns Quick Access Controls, and Folks are Happy Kellen | usagoldmine...
This Free App Archives and Deletes Your Tweets Justin Pot | usagoldmines.com
Now Is the Best Time to Get a Deal on a Used Car Emily Long | usagoldmines.com
The MacRumors Show: Apple's 2024 – Year in Review Hartley Charlton | usagoldmines.com
M2 iPad Air Holiday Deals Include $100 Off and All-Time Low Prices at Best Buy Mitchel Broussard | u...
Civil societies warn against EU plans to make digital devices monitorable at all times chiara.castro...
Prime Video is testing a great new feature that'll use AI to better recommend movies and shows | us...
eM Client boosts email offerings with Postbox acquisition udinmwenefosa@gmail.com (Efosa Udinmwen) |...
Project Moohan shows Samsung doesn’t understand what makes the Meta Quest 3 special – and I don't t...
Where is Apple CarPlay 2? A 2024 launch is looking unlikely, but not impossible alexblake.techradar@...
Apple forced to patch iOS and macOS security flaw that could have leaked your private info | usagol...
Astro Bot takes home four major awards at The Game Awards 2024, including Game of the Year | usagol...
Americans spend more years being unhealthy than people in any other country Beth Mole | usagoldmines...
F1 Arcade trip report: Great sims make for a compelling experience Jonathan M. Gitlin | usagoldmines...
Don’t use crypto to cheat on taxes: Bitcoin bro gets 2 years Ashley Belanger | usagoldmines.com
Elon Musk slams SEC as agency threatens charges in Twitter stock probe Jon Brodkin | usagoldmines.co...
Best PCIe 4.0 SSDs 2024: Top picks from experts | usagoldmines.com
Get festive with these magical Christmas tree lights for 35% off | usagoldmines.com
Does it really matter what thermal paste you use in your gaming PC? | usagoldmines.com
Seven Ways to Make Hosting Little Kids for the Holidays Less Stressful for Everyone Jason Keil | usa...
The 28 Best Holiday and Christmas Movies on Netflix Right Now Ross Johnson | usagoldmines.com
Best Buy Takes Up to $200 Off M4 iPad Pro, Available From $849 Mitchel Broussard | usagoldmines.com
New Galaxy S25 leak suggests there'll be no Slim model after all, but I'm not convinced jamie.richar...
Image Playground made me a wizard but I’m still waiting for that Siri magic lance.ulanoff@futurenet....
Amazon pauses $1bn Microsoft 365 rollout following Russian security concerns | usagoldmines.com
Split Fiction is a new co-op game from the studio behind the award-winning It Takes Two | usagoldmi...
The US military is now talking openly about going on the attack in space Stephen Clark | usagoldmine...
Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

Leave a Reply