Tuesday, July 23, 2013

Apple’s OS X FBI Ransomware Goes Global

form blog.malwarebytes.org

Last week we blogged about how Apple’s Mac OS X users are vulnerable to the FBI Ransomware attacks. These social engineering scams come in the form of a stern warning from the FBI stating you have been caught doing something illegal. The user’s machine is then locked and a ransom of $300 must be paid to restore normal access to the computer.

The ransom pages came with two designs based on the victim’s geolocation: FBI or Europol.

Today, I discovered further customizations showing that the bad guys are busy updating their templates for each country’s police force.
sample: click to enlarge

A couple things to note:

Google has updated their Google Chrome on Mac and can now defeat the ransom page. You can close it despite the JavaScript loop that attempts to prompt you 150 times.

Safari users are still stuck and must employ one of the two methods described here to get rid of the page.

Not all countries currently have their own ‘theme’ but it is only a matter of time before the bad guys roll them out.

Last week the Internet Crime Complaint Center (IC3) issued a warning that the FBI would never use such methods to apprehend criminals. It is a reminder that user awareness is the best protection against these attacks.


  1. hi...Im student from Informatics engineering nice article,
    thanks for sharing :)

  2. I work in computer department of cosmetics company in China. All 15 of our macs became infected with this. do you no of a fix please?