{"id":3403,"date":"2014-05-28T14:07:02","date_gmt":"2014-05-28T18:07:02","guid":{"rendered":"http:\/\/me-en.kaspersky.com\/blog\/?p=3403"},"modified":"2017-09-24T18:20:51","modified_gmt":"2017-09-24T14:20:51","slug":"ransomware_targets_ios_osx","status":"publish","type":"post","link":"https:\/\/me-en.kaspersky.com\/blog\/ransomware_targets_ios_osx\/3403\/","title":{"rendered":"Ransomware Malware Targets Apple Users"},"content":{"rendered":"<p>A new piece of ransomware is targeting Apple users, mostly in Australia. Infected users are reportedly seeing a warning message in place of their homescreens offering to unlock affected devices if the user pays a fee between $50 and $100.<\/p>\n<p style=\"text-align: center\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2014\/05\/05111254\/ransomwareapple-1.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4905 size-full\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2014\/05\/05111254\/ransomwareapple-1.jpg\" alt=\"ransomwareapple\" width=\"640\" height=\"480\"><\/a><\/p>\n<p>According to reports, users first became aware of these infections early yesterday after their iOS and OSX devices\u2019 \u201cFind My iPhone\u201d sound alert began going off. Upon looking at their phone screens, users were presented with a message saying: \u201cHacked by Oleg Pliss. For unlock YOU NEED send voucher code by 100 $\/eur one of this (Moneypack\/Ukash\/PaySafeCard) to helplock@gmx.com I sent code 2618911226.\u201d<\/p>\n<p style=\"text-align: center\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2014\/05\/05102528\/iOS_OSX-Ransomware.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-4904 size-full\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2014\/05\/05102528\/iOS_OSX-Ransomware.png\" alt=\"iOS_OSX Ransomware\" width=\"368\" height=\"561\"><\/a><\/p>\n<p>It\u2019s not clear how hackers have managed to compromise affected devices, but the general consensus is that the attackers are leveraging access to users iCloud accounts in order to exploit the phones themselves. It\u2019s also not clear who Oleg Pliss is or if that is even a real person.<\/p>\n<p>Ransomware refers to a class of malware that locks down an infected machine and demands some sort of payment to unlock it. In some cases, the malware merely renders a computer unusable or places some sort of blocker in the way of the user and his or her applications. In others \u2013 like the case of CryptoLocker \u2013 the ransomware encrypts important files on the infected machine and demands payment for the private key that would decrypt those files.<\/p>\n<p>Paying these ransoms is generally viewed as a bad idea, because you never actually know if anything will get decrypted. This is one of the reasons we always recommend creating regular back-ups of your data. If you have a recent copy of all your data on an external hard drive or some cloud service, then you can just roll your computer back or reinstall the operating system.\u00a0<\/p><blockquote class=\"twitter-pullquote\"><p>A new piece of #ransomware #malware is targeting #Apple users.<\/p><a href=\"https:\/\/twitter.com\/share?url=https%3A%2F%2Fkas.pr%2F6bAK&amp;text=A+new+piece+of+%23ransomware+%23malware+is+targeting+%23Apple+users.\" class=\"btn btn-twhite\" data-lang=\"en\" data-count=\"0\" target=\"_blank\" rel=\"noopener nofollow\">Tweet<\/a><\/blockquote>\n<p>According to the Sydney Morning Herald, iPhone users in Queensland, NSW, Western Australia, South Australia and Victoria have been targeted by the scheme while several other reports claim users in New Zealand have also been hit. Thus far, users in the U.S. and Europe seem unaffected at the moment, though we wouldn\u2019t be surprised if the problem spread to other continents.<\/p>\n<p>As noted by Chris Brook at Threatpost.com, recent attacks against Adobe and eBay and others have spilled encrypted user passwords. If these passwords were in some way decrypted \u2013 and users had shared passwords between services \u2013 then the passwords could be easily used in brute force attacks to access online accounts like iCloud. To be clear, affected users would have had to use the same passwords. It\u2019s not clear if there is a connection between these hacks, but in the past, password-spilling data breaches \u2013 both known and unknown \u2013 have led to online account breaches elsewhere.<\/p>\n<p>If the attack were relying on iCloud account access, that service\u2019s two-factor authentication feature would provide a pretty solid defense. In fact, now might be a good time to turn on two-factor authentication for your iCloud account. Below you\u2019ll find a short screencast that shows you exactly how you can get that process started (we stop just before actually turning on two factor in the video, but I am sure you can figure the rest out).<\/p>\n<p style=\"text-align: center\"><span class=\"embed-youtube\" style=\"text-align:center; display: block;\"><iframe class=\"youtube-player\" type=\"text\/html\" width=\"640\" height=\"390\" src=\"https:\/\/www.youtube.com\/embed\/APLl2fPAH2g?version=3&amp;rel=1&amp;fs=1&amp;showsearch=0&amp;showinfo=1&amp;iv_load_policy=1&amp;wmode=transparent\" frameborder=\"0\" allowfullscreen=\"true\"><\/iframe><\/span><\/p>\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>New ransomware targets Apple users running iOS mobile and O SX Mac devices with a piece of malware that blocks use and demands payments.<\/p>\n","protected":false},"author":42,"featured_media":3404,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,9],"tags":[14,1061,100,26,34,36,114,433],"class_list":{"0":"post-3403","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-tips","9":"tag-apple","10":"tag-ios","11":"tag-ipad","12":"tag-iphone","13":"tag-mac","14":"tag-malware-2","15":"tag-os-x","16":"tag-ransomware"},"hreflang":[{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/ransomware_targets_ios_osx\/3403\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/ransomware_targets_ios_osx\/3513\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/ransomware_targets_ios_osx\/3831\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/ransomware_targets_ios_osx\/4000\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/ransomware_targets_ios_osx\/4903\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/ransomware_targets_ios_osx\/3783\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/ransomware_targets_ios_osx\/4903\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/ransomware_targets_ios_osx\/4903\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/me-en.kaspersky.com\/blog\/tag\/apple\/","name":"apple"},"_links":{"self":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/3403","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/42"}],"replies":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=3403"}],"version-history":[{"count":1,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/3403\/revisions"}],"predecessor-version":[{"id":7034,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/3403\/revisions\/7034"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/3404"}],"wp:attachment":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=3403"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=3403"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=3403"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}