The HandBrake for Mac Proton RAT Compromise

Updated 5 Oct 2026 · Incident date 2 May 2017 · vendor binary

PackageHandBrake 1.0.7 for macOS (HandBrake-1.0.7.dmg) served from download.handbrake.fr, 2-6 May 2017
FileHandBrake.app inside HandBrake-1.0.7.dmg, rebuilt to ca...

HandBrake-1.0.7.dmg, served from the mirror download.handbrake.fr between 2 and 6 May 2017, carried the Proton remote access trojan for macOS.

The primary mirror was not affected. The HandBrake team told users who downloaded in that window that they had a 50/50 chance of infection.

What happened

Attackers compromised one download mirror and replaced the HandBrake installer for Mac with a copy that carried malware. Help Net Security gives the exposure window as 02 May 2017 14:30 UTC to 06 May 2017 11:00 UTC. CSO reports the same window in US Eastern time. The affected file was HandBrake-1.0.7.dmg from download.handbrake.fr.

The malware was Proton RAT. BleepingComputer reports that it let attackers steal data and open VNC and SSH connections. Help Net Security adds keystroke monitoring, file upload and download, and webcam control. It could show fake authentication windows. CSO reports that researchers saw genuine Apple code-signing signatures on the malware.

The built-in updater was safe. Version 0.10.6 and later check a DSA signature, so users who updated through the app were protected. Apple later added XProtect signatures for Proton variants, per Help Net Security. Read BleepingComputer, Help Net Security and CSO.

A clean 1.0.7 build existed on the primary mirror. The poisoned copy had extra code that asked for a password and gave remote access. A comparison of the two app bundles shows that difference.

Affected versions

The sources name only the Mac DMG.

Indicators of compromise

How to check

Hash the DMG you downloaded and look for the malware files. Compare the hash with the SHA-256 above.

shasum -a 256 ~/Downloads/HandBrake-1.0.7.dmg
ls ~/Library/RenderFiles/activity_agent.app ~/Library/LaunchAgents/fr.handbrake.activity_agent.plist; pgrep -il activity_agent

A hash match, any of these files, or a running Activity_agent process means you are infected.

What to do now

  1. Run the removal steps from the HandBrake team: launchctl unload ~/Library/LaunchAgents/fr.handbrake.activity_agent.plist then rm -rf ~/Library/RenderFiles/activity_agent.app.
  2. Delete ~/Library/VideoFrameworks/proton.zip if it exists.
  3. Delete every HandBrake.app copy that came from the bad DMG.
  4. Change every password stored in the macOS Keychain and in your browsers. The HandBrake team states you must do this.
  5. Run an up-to-date Mac antivirus scan, and install HandBrake from a verified source.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old HandBrake-prev --new HandBrake-current
files scanned: 59

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    HandBrake.app
           It now downloads from the internet and reads saved passwords and access keys. It did not before.

Frequently asked questions

Which HandBrake version was infected with Proton RAT?

HandBrake 1.0.7 for macOS, in the file HandBrake-1.0.7.dmg, downloaded from download.handbrake.fr between 2 and 6 May 2017.

How do I know if HandBrake infected my Mac?

Look for a process named Activity_agent in Activity Monitor, or the folder ~/Library/RenderFiles/activity_agent.app. Also check that the DMG SHA-256 is not 013623e5e50449bbdf6943549d8224a122aa6c42bd3300a1bd2b743b01ae6793.

How do I remove the HandBrake Proton RAT?

Unload the launch agent fr.handbrake.activity_agent.plist, delete ~/Library/RenderFiles/activity_agent.app, delete HandBrake.app, and change all Keychain and browser passwords.

Sources

  1. bleepingcomputer.com/news/security/website-of-handbrake-app-hacked-to-spread-proton-rat-for-mac-users/
  2. helpnetsecurity.com/2017/05/08/handbrake-infected/
  3. csoonline.com/article/561559/handbrake-mirror-server-hacked-to-serve-up-proton-rat-for-macs.html

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free