The Transmission 2.90 KeRanger Ransomware Attack

Updated 5 Oct 2026 · Incident date 4 Mar 2016 · vendor binary

PackageTransmission for Mac 2.89 -> 2.90 (Transmission-2.90.dmg served from transmissionbt.com 2016-03-04/05)
FileTransmission.app/Contents/Resources/General.rtf

Transmission for Mac 2.90 carried KeRanger, the first fully working ransomware seen on OS X. The installer Transmission-2.90.dmg was served from the official site on 4 and 5 March 2016.

Palo Alto Networks found it on 4 March 2016. The ransomware waits three days before it contacts its servers and encrypts files.

What happened

The official Transmission 2.90 download contained a program disguised as a document. Unit 42 reports that the infection window ran from 11:00 AM PST on 4 March to 7:00 PM PST on 5 March 2016. The file General.rtf in Transmission.app/Contents/Resources/ was a Mach-O executable, not a document. Wikipedia adds that it was packed with UPX 3.91.

The installer was signed with a valid Apple-issued developer certificate (Developer ID Z7276PX673, a Turkish company) that Unit 42 says was created on the morning of 4 March 2016. Apple revoked it later. Because of the valid signature, macOS Gatekeeper did not block it.

When the app ran, it copied the executable to ~/Library/kernel_service and started it. Then it waited three days. After that it contacted command servers on Tor, encrypted files with RSA and AES, and asked for one bitcoin, about 400 US dollars. Unit 42 says it targeted more than 300 file extensions. BleepingComputer reports that it scanned /Users and /Volumes, including external drives. It added .encrypted to file names and left a README_FOR_DECRYPT.txt note in each folder. Wikipedia reports more than 7,000 victims. Wikipedia also says the Transmission team released a new download and pushed an update.

Read Unit 42, BleepingComputer and Wikipedia.

Version 2.89 was clean. In 2.90 the app gained a hidden executable and launcher code to copy and run it. A file-by-file comparison of the two app bundles shows a new Mach-O file named like a document.

Affected versions

Version 2.89 was clean. The sources do not name the fixed release number.

Indicators of compromise

How to check

Look for the fake document and the dropped files.

ls -la /Applications/Transmission.app/Contents/Resources/General.rtf ~/Library/kernel_service ~/Library/.kernel_*
pgrep -l kernel_service

Any listed file, or a running kernel_service process, means the Mac ran KeRanger. If General.rtf is present, run file on it. A real document is not a Mach-O executable.

What to do now

  1. Quit Transmission and delete Transmission.app if it is version 2.90.
  2. Delete ~/Library/kernel_service and the .kernel_pid, .kernel_time and .kernel_complete files.
  3. If files are encrypted, restore them from a backup. The sources report no free decryption at that time.
  4. Install a current Transmission release from the official site, then compare its hash with the one the project publishes.
  5. Keep offline backups so ransomware cannot reach them.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Mac-2.89 --new Mac-2.90
files scanned: 11

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    Transmission.app
           It now downloads from the internet and reads saved passwords and access keys. It did not before.

Frequently asked questions

Which Transmission version had KeRanger ransomware?

Transmission for Mac 2.90, in the installer Transmission-2.90.dmg, downloaded on 4 and 5 March 2016.

How do I check if KeRanger infected my Mac?

Look for General.rtf in Transmission.app/Contents/Resources, a process named kernel_service, and the file ~/Library/kernel_service.

How long does KeRanger wait before it encrypts files?

Unit 42 and BleepingComputer report that it waits three days before it contacts its servers and encrypts files.

Sources

  1. unit42.paloaltonetworks.com/new-os-x-ransomware-keranger-infected-transmission-bittorrent-client-installer/
  2. bleepingcomputer.com/news/security/information-about-the-keranger-os-x-ransomware-and-how-to-remove-it/
  3. en.wikipedia.org/wiki/KeRanger

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free