The modified copy of Transmission includes a file named General.rtf, which is actually an executable file rather than the rich-text document it pretends to be. When the app is launched, this file is copied to a file named kernel_service in the user Library folder (which is hidden by default on recent versions of OS X)."
Read the full story here: https://blog.malwarebytes.org/mac/2016/03/first-mac-ransomware-spotted/
No comments:
Post a Comment