The Transmission for Mac OSX/Keydnap Attack
Updated 5 Oct 2026 · Incident date 29 Aug 2016 · vendor binary
Transmission for Mac 2.92 (genuine) -> recompiled Transmission2.92.dmg served from the official site 2016-08-29Transmission.app/Contents/Resources/License.rtfA trojanized Transmission 2.92 disk image, Transmission2.92.dmg, carried the OSX/Keydnap malware. It was served from the official Transmission website and distributed on 29 August 2016. The app bundle was signed on 28 August.
The malware steals the macOS keychain contents and sets up a persistent backdoor.
What happened
ESET reports that the BitTorrent client Transmission was compromised on its official website. Attackers added a block of malicious code to the main function of the application. ESET compares the method to the earlier KeRanger attack. The malicious file is named License.rtf inside the app, but it is an executable and not a document.
ESET identifies the malware as Keydnap version 1.5. It steals the contents of the OS X keychain and keeps remote access. This version also added a standalone Tor client and the ability to receive an updated command address. It communicates through a Tor hidden service at an .onion address, using HTTP POST with RC4 encryption.
The legitimate disk image uses a hyphen in its name, Transmission-2.92.dmg. The malicious image has no hyphen.
Affected versions
The affected item is the disk image Transmission2.92.dmg from 29 August 2016. It is a recompiled build of version 2.92. The genuine 2.92 build is the clean baseline.
- Malicious:
Transmission2.92.dmg(no hyphen) - Genuine:
Transmission-2.92.dmg(with a hyphen)
Indicators of compromise
Transmission2.92.dmgSHA-1:1ce125d76f77485636ecea330acb038701ccc4ce- Dropper SHA-1:
e0ef6a5216748737f5a3c8d08bbdf204d039559e - Backdoor SHA-1:
8ca03122ee73d3e522221832872b9ed0c9869ac4 ~/Library/Application Support/com.apple.iCloud.sync.daemon/~/Library/LaunchAgents/com.apple.iCloud.sync.daemon.plist~/Library/LaunchAgents/com.geticloud.icloud.photo.plist- Processes named
icloudproc,License.rtfandicloudsyncd
How to check
Look for the persistence files that ESET names.
ls -d ~/Library/Application\ Support/com.apple.iCloud.sync.daemon ~/Library/LaunchAgents/com.apple.iCloud.sync.daemon.plist ~/Library/LaunchAgents/com.geticloud.icloud.photo.plist 2>/dev/null
Then check for the running processes.
pgrep -fl "icloudproc|icloudsyncd|License.rtf"
If you still have the disk image, hash it with shasum Transmission2.92.dmg and compare the value with the one above.
What to do now
- Quit Transmission.
- Stop the processes
icloudproc,License.rtfandicloudsyncd. - Delete the files and folders listed above.
- Reinstall Transmission from a verified source and check its signature.
- Treat the keychain as stolen. Change the passwords stored in it.
Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here the bundle gained an executable disguised as a licence file. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 85 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED Transmission.app It now reads saved passwords and access keys, runs other programs and restarts itself after a reboot. It did not before.
Frequently asked questions
What happened to Transmission for Mac in 2016?
A trojanized Transmission2.92.dmg on the official site carried OSX/Keydnap, which steals the keychain and keeps a backdoor. It was distributed on 29 August 2016.
How do I check for OSX/Keydnap?
Look for the com.apple.iCloud.sync.daemon folder in Application Support, the two launch agent plist files named by ESET, and the processes icloudproc and icloudsyncd.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.