Mac Anti-Ransomware Tool Released, but Needs More Work

Worried that ransomware might infect your Mac? Then you might want to try famed Mac hacker Patrick Wardle's new RansomWhere tool, which will try to detect and stop encrypting ransomware dead in its tracks.

Credit: Dragon Image/Shutterstock

(Image credit: Dragon Image/Shutterstock)

"Unless you've been living under an infosec rock, you're likely aware that ransomware is somewhat of a problem — to put it mildly," Wardle, a researcher with Silicon Valley security firm Synack, wrote in a blog post. "There are already claims that '2016 is shaping up as the year of ransomware' and that 'this is basically becoming a national cyber emergency.'"

However, Wardle's own tool may have its limitations. Pedro Vilaca, a Portuguese Mac hacker, posted a video showing a quick and easy way around RansomWhere this morning (April 20), only a few hours after Wardle had unveiled his utility.

MORE: What Is Ransomware and How Can I Protect Myself?

Several strains of encrypting ransomware have been targeting Windows PCs and servers, and more recently Linux servers, all across North America. Hospitals, schools and municipal government agencies have had to pay thousands of dollars to free their files, and the average PC user often must pay a few hundred dollars to regain access to his or her documents.

Macs aren't immune to this threat. In March, we saw KeRanger, the first known piece of encrypting ransomware targeting Macs "in the wild." It didn't work entirely properly, but the next strain of Mac ransomware will be more effective.

So Wardle took a hint from security-software makers Malwarebytes and Bitdefender, which have released their own ransomware-detection tools for Windows, and created his own, free anti-ransomware tool for OS X.

RansomWhere? (the question mark is part of the name, but we'll not use it from now on) starts upon boot and runs in the background to keep an eye out for non-Apple-approved processes that start rapidly encrypting files in the user's Home directory.

"If we can monitor file I/O [input/output] events and detect the rapid creation of encrypted files by untrusted processes, then ransomware may be generically detected," Wardle figured.

If RansomWhere spots such a process, it will suspend the process and pop up an alert window to notify the user. The window will show the file path of the suspect process, and the file paths of those that have already been encrypted.

If the user recognizes the encryption process as legitimate, he or she can click Allow to let the process resume. If not, he or she can click Terminate to end the process.

Credit: Patrick Wardle

(Image credit: Patrick Wardle)

Vilaca's video, however, showed that he had created a proof-of-concept piece of ransomware called RansomNowhere that encrypted files in Vilaca's own Home folder.

"RansomWhere is a cool attempt but it's very much flawed," Vilaca tweeted. "Look at it as a PoC [proof of concept] and that's it."

Wardle hadn't responded to Vilaca's demonstration by the time of this piece's publication, but he did warn in his blog posts that RansomWhere was just the beginning.

"Both this research and tool are version 1.0, meaning likely room for improvement," Wardle wrote.

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Latest in News
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Sunday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)