The Transmission for Mac OSX/Keydnap Attack

Updated 5 Oct 2026 · Incident date 29 Aug 2016 · vendor binary

PackageTransmission for Mac 2.92 (genuine) -> recompiled Transmission2.92.dmg served from the official site 2016-08-29
FileTransmission.app/Contents/Resources/License.rtf

A trojanized Transmission 2.92 disk image, Transmission2.92.dmg, carried the OSX/Keydnap malware. It was served from the official Transmission website and distributed on 29 August 2016. The app bundle was signed on 28 August.

The malware steals the macOS keychain contents and sets up a persistent backdoor.

What happened

ESET reports that the BitTorrent client Transmission was compromised on its official website. Attackers added a block of malicious code to the main function of the application. ESET compares the method to the earlier KeRanger attack. The malicious file is named License.rtf inside the app, but it is an executable and not a document.

ESET identifies the malware as Keydnap version 1.5. It steals the contents of the OS X keychain and keeps remote access. This version also added a standalone Tor client and the ability to receive an updated command address. It communicates through a Tor hidden service at an .onion address, using HTTP POST with RC4 encryption.

The legitimate disk image uses a hyphen in its name, Transmission-2.92.dmg. The malicious image has no hyphen.

Affected versions

The affected item is the disk image Transmission2.92.dmg from 29 August 2016. It is a recompiled build of version 2.92. The genuine 2.92 build is the clean baseline.

Indicators of compromise

How to check

Look for the persistence files that ESET names.

ls -d ~/Library/Application\ Support/com.apple.iCloud.sync.daemon ~/Library/LaunchAgents/com.apple.iCloud.sync.daemon.plist ~/Library/LaunchAgents/com.geticloud.icloud.photo.plist 2>/dev/null

Then check for the running processes.

pgrep -fl "icloudproc|icloudsyncd|License.rtf"

If you still have the disk image, hash it with shasum Transmission2.92.dmg and compare the value with the one above.

What to do now

  1. Quit Transmission.
  2. Stop the processes icloudproc, License.rtf and icloudsyncd.
  3. Delete the files and folders listed above.
  4. Reinstall Transmission from a verified source and check its signature.
  5. Treat the keychain as stolen. Change the passwords stored in it.

Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here the bundle gained an executable disguised as a licence file. See all attacks.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Transmission-prev --new Transmission-current
files scanned: 85

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    Transmission.app
           It now reads saved passwords and access keys, runs other programs and restarts itself after a reboot. It did not before.

Frequently asked questions

What happened to Transmission for Mac in 2016?

A trojanized Transmission2.92.dmg on the official site carried OSX/Keydnap, which steals the keychain and keeps a backdoor. It was distributed on 29 August 2016.

How do I check for OSX/Keydnap?

Look for the com.apple.iCloud.sync.daemon folder in Application Support, the two launch agent plist files named by ESET, and the processes icloudproc and icloudsyncd.

Sources

  1. welivesecurity.com/2016/08/30/osxkeydnap-spreads-via-signed-transmission-application/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free