The Transmission 2.90 KeRanger Ransomware Attack
Updated 5 Oct 2026 · Incident date 4 Mar 2016 · vendor binary
Transmission for Mac 2.89 -> 2.90 (Transmission-2.90.dmg served from transmissionbt.com 2016-03-04/05)Transmission.app/Contents/Resources/General.rtfTransmission for Mac 2.90 carried KeRanger, the first fully working ransomware seen on OS X. The installer Transmission-2.90.dmg was served from the official site on 4 and 5 March 2016.
Palo Alto Networks found it on 4 March 2016. The ransomware waits three days before it contacts its servers and encrypts files.
What happened
The official Transmission 2.90 download contained a program disguised as a document. Unit 42 reports that the infection window ran from 11:00 AM PST on 4 March to 7:00 PM PST on 5 March 2016. The file General.rtf in Transmission.app/Contents/Resources/ was a Mach-O executable, not a document. Wikipedia adds that it was packed with UPX 3.91.
The installer was signed with a valid Apple-issued developer certificate (Developer ID Z7276PX673, a Turkish company) that Unit 42 says was created on the morning of 4 March 2016. Apple revoked it later. Because of the valid signature, macOS Gatekeeper did not block it.
When the app ran, it copied the executable to ~/Library/kernel_service and started it. Then it waited three days. After that it contacted command servers on Tor, encrypted files with RSA and AES, and asked for one bitcoin, about 400 US dollars. Unit 42 says it targeted more than 300 file extensions. BleepingComputer reports that it scanned /Users and /Volumes, including external drives. It added .encrypted to file names and left a README_FOR_DECRYPT.txt note in each folder. Wikipedia reports more than 7,000 victims. Wikipedia also says the Transmission team released a new download and pushed an update.
Read Unit 42, BleepingComputer and Wikipedia.
Version 2.89 was clean. In 2.90 the app gained a hidden executable and launcher code to copy and run it. A file-by-file comparison of the two app bundles shows a new Mach-O file named like a document.
Affected versions
- Transmission for Mac 2.90, as
Transmission-2.90.dmg. - Downloaded from the official site from 11:00 AM PST on 4 March to 7:00 PM PST on 5 March 2016.
Version 2.89 was clean. The sources do not name the fixed release number.
Indicators of compromise
- File
/Applications/Transmission.app/Contents/Resources/General.rtf - Process
kernel_serviceand file~/Library/kernel_service - Files
~/Library/.kernel_pid,~/Library/.kernel_time,~/Library/.kernel_complete - Ransom note
README_FOR_DECRYPT.txtand the.encryptedfile extension. - Tor addresses:
lclebb6kvohlkcml.onion[.]link,bmacyzmea723xyaz.onion[.]link,nejdtkok7oz5kjoc.onion[.]link - SHA-256 values listed by Unit 42:
d1ac55a4e610380f0ab239fcc1c5f5a42722e8ee1554cba8074bbae4a5f6dbe1,e3ad733cea9eba29e86610050c1a15592e6c77820927b9edeb77310975393574,31b6adb633cff2a0f34cefd2a218097f3a9a8176c9363cc70fe41fe02af810b9,d7d765b1ddd235a57a2d13bd065f293a7469594c7e13ea7700e55501206a09b5,ddc3dbee2a8ea9d8ed93f0843400653a89350612f2914868485476a847c6484a,6061a554f5997a43c91f49f8aaf40c80a3f547fc6187bee57cd5573641fcf153
How to check
Look for the fake document and the dropped files.
ls -la /Applications/Transmission.app/Contents/Resources/General.rtf ~/Library/kernel_service ~/Library/.kernel_*
pgrep -l kernel_service
Any listed file, or a running kernel_service process, means the Mac ran KeRanger. If General.rtf is present, run file on it. A real document is not a Mach-O executable.
What to do now
- Quit Transmission and delete
Transmission.appif it is version 2.90. - Delete
~/Library/kernel_serviceand the.kernel_pid,.kernel_timeand.kernel_completefiles. - If files are encrypted, restore them from a backup. The sources report no free decryption at that time.
- Install a current Transmission release from the official site, then compare its hash with the one the project publishes.
- Keep offline backups so ransomware cannot reach them.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 11 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED Transmission.app It now downloads from the internet and reads saved passwords and access keys. It did not before.
Frequently asked questions
Which Transmission version had KeRanger ransomware?
Transmission for Mac 2.90, in the installer Transmission-2.90.dmg, downloaded on 4 and 5 March 2016.
How do I check if KeRanger infected my Mac?
Look for General.rtf in Transmission.app/Contents/Resources, a process named kernel_service, and the file ~/Library/kernel_service.
How long does KeRanger wait before it encrypts files?
Unit 42 and BleepingComputer report that it waits three days before it contacts its servers and encrypts files.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.