Jump to content

Transmission v2.90 for OS X contains malware


Recommended Posts

Posted

Sources: Transmission Website & Forum

 

Everyone running 2.90 on OS X should immediately upgrade to 2.91 or delete their copy of 2.90, as they may have downloaded a malware-infected file.

 

Using “Activity Monitor” preinstalled in OS X, check whether any process named “kernel_service” is running. If so, double check the process, choose the “Open Files and Ports” and check whether there is a file name like “/Users//Library/kernel_service”. If so, the process is KeRanger’s main process. We suggest terminating it with “Quit -> Force Quit”.

Posted (edited)

How to check the integrity of your Mac

 

To check if you have downloaded a compromised version of the software, go to the Utilities folder in your Applications and launch the Activity Monitor. In the search, enter:

kernel_service

 

If you find this process, click the "i" button in the window of the Activity Monitor, go to File, "Open Ports" (?) and search for:

Users//Library/kernel_service

 

If you find this, force-quit it and update Transmission. That is KeRanger, which you've eliminated by force-quitting and crushing the compromised version of Transmission.

Edited by Carter
  • 5 months later...
Posted

Transmission has been infected again!

 

OSX/Keydnap spreads via signed Transmission application

 

Literally minutes after being notified by ESET, the Transmission team removed the malicious file from their web server and launched an investigation to identify how this happened. At the time of writing, it was impossible to tell exactly when the malicious file was made available for download. According to the signature, the application bundle was signed on August 28th, 2016, but it seems to have been distributed only the next day. Thus, we advise anyone who downloaded Transmission v2.92 between 28th August and 29th August 2016, inclusively, to verify if their system is compromised by testing the presence of any of the following file or directory:

/Applications/Transmission.app/Contents/Resources/License.rtf
/Volumes/Transmission/Transmission.app/Contents/Resources/License.rtf
$HOME/Library/Application Support/com.apple.iCloud.sync.daemon/icloudsyncd
$HOME/Library/Application Support/com.apple.iCloud.sync.daemon/process.id
$HOME/Library/LaunchAgents/com.apple.iCloud.sync.daemon.plist
/Library/Application Support/com.apple.iCloud.sync.daemon/
$HOME/Library/LaunchAgents/com.geticloud.icloud.photo.plist

If any of them exists, it means the malicious Transmission application was executed and that Keydnap is most likely running. Also note that the malicious disk image was named Transmission2.92.dmg while the legitimate one is Transmission-2.92.dmg (notice the hyphen).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...