LockBit tests first macOS ransomware build
Researchers dissected an early, non-functional LockBit ransomware sample compiled for Apple Silicon, confirming it's a test build with no real-world threat to macOS users.
Following a tweet from @MalwareHunterTeam, researcher Patrick Wardle analyzed "locker_Apple_M1_64", an arm64 Mach-O binary appearing to be the first macOS-targeting build from the LockBit ransomware operation. Reverse engineering revealed the sample is largely a recompiled port of LockBit's Windows/Linux/ESXi encryptor, retaining Windows-specific artifacts (autorun.inf, ntuser.dat.log) and no macOS-specific logic beyond a config blob. The binary is only ad-hoc signed, meaning Gatekeeper blocks execution by default, and it lacks any awareness of macOS protections such as SIP or TCC.
Dynamic analysis confirmed the sample does function as ransomware when manually executed and unsigned protections bypassed: it encrypts files, appends a .lockbit extension, and drops a ransom note. However, the binary contains bugs including buffer overflows causing crashes, and Cisco Talos told BleepingComputer the encryptor was a test/beta build never intended for live deployment. LockBit's public representative, LockBitSupp, confirmed the macOS variant is "actively being developed," indicating this is an early step toward future macOS targeting rather than an active campaign.
While the current sample poses no meaningful risk to macOS users due to its lack of code-signing validity and TCC/SIP awareness, its existence signals that a major ransomware gang is investing in macOS capability. The author notes existing generic ransomware detection tools (e.g., RansomWhere?) already catch this sample's file-encryption behavior, underscoring that behavioral detection remains effective even against novel platform ports.
Mentioned in this report
Source reporting: https://objective-see.org/blog/blog_0x75.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free