Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

NotLockBit Ransomware Can Target macOS Devices

A file-encrypting malware family posing as the LockBit ransomware has been observed targeting macOS systems.

A new macOS malware family capable of encrypting files and pretending to be the LockBit ransomware is making the rounds, security researchers warn.

Written in Go and targeting both Windows and macOS systems, the threat employs the tactics typically observed in ransomware operations: it steals victim data for double extortion, encrypts files, and deletes shadow copies to prevent data recovery.

What makes the new malware family stand out from the crowd is the impersonation of LockBit, the notorious ransomware that was disrupted by law enforcement in February and September 2024.

According to SentinelOne, which calls it NotLockBit, the malware is distributed as an x86_64 binary, which suggests it only works on Intel and Apple silicon macOS devices running the Rosetta emulation software.

The threat was seen harvesting system information upon execution and using a public key to encrypt a randomly generated master key that is used during the file encryption process.

By relying on RSA asymmetric encryption, the threat actor behind NoLockBit ensures that the master key cannot be decrypted without the attacker-held private key.

Advertisement. Scroll to continue reading.

NotLockBit appends the .abcd extension to the encrypted files, drops a ransom note in each folder containing encrypted files, and attempts to replace the desktop wallpaper to display a LockBit 2.0 banner.

In a recent report, Trend Micro revealed that, prior to starting the encryption process, the ransomware would exfiltrate the victim’s data to an attacker-controlled Amazon S3 bucket, using hardcoded AWS credentials.

“We suspect the ransomware author to be either using their own AWS account or a compromised AWS account. We came across more than thirty samples possibly from the same author, signaling that this ransomware is being actively developed and tested,” Trend Micro warned.

The cybersecurity firm reported the observed activity to AWS, which suspended both the AWS access keys and the associated account.

According to SentinelOne, NotLockBit appears to be the first functional ransomware family targeting macOS systems, as previously observed attempts were mere proof-of-concept (PoC) samples.

“The NotLockBit malware appears to be very much in development. For now, the threat actor’s AWS accounts have been removed and there are no known victims or distribution methods in the wild. Given the amount of development that has gone into this threat so far, we would be surprised not to see more from this threat actor in the short to medium term,” SentinelOne notes.

Related: BlackCat Ransomware Successor Cicada3301 Emerges

Related: Ukrainian Malware Operator Pleads Guilty in US Court

Related: Industrial Giant Thyssenkrupp Again Targeted by Cybercriminals

Related: Electric Motor Giant Nidec Confirms Data Stolen in Ransomware Attack

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.