In the past few years, LockBit has become the largest and most aggressive ransomware group. Although it has been active on Windows, Linux and virtual hosts before, it seems from recent developments that the organization has developed the first ransomware for Mac systems. If you are a Mac user, don’t forget to be vigilant and be cautious.

LockBit ransomware group appears to be targeting Macs for the first time
MalwareHunterTeam Recently, it was discovered that the first ransomware version designed for macOS has appeared on the Internet. While it’s not entirely clear yet, this could also be the first time a major ransomware group has targeted Apple devices. For context, security analysts believe that LickBit is a Russian-based organization with most members communicating in Russian, but its leaders have stated that they operate in the United States or China.
“locker_Apple_M1_64”: 3e4bbd21756ae30c24ff7d6942656be024139f8180b7bddd4e5c62a9dfbd8c79
As much as I can tell, this is the first Apple’s Mac devices targeting build of LockBit ransomware sample seen…
Also is this a first for the “big name” gangs?
🤔@patrickwardle
cc @cyb3rops pic.twitter.com/SMuN3Rmodl— MalwareHunterTeam (@malwrhunterteam) April 15, 2023
LockBit has been developing a ransomware-as-a-service (RaaS) operation, an approach that means the group allows others to exploit their ransomware for a fee. It appears that this LockBit ransomware was created for Apple Silicon-based Macs and is named “locker_Apple_M1_64.”

While Twitter users focused on information security vx-underground This ransomware was mentioned in November 2022. But MalwareHunterTeam says they haven’t seen any mention of it online.9to5Mac The same thing was found, so the conclusion is that if it has been there since last fall, it is probably hiding out of sight of the radar and doing its evil.
Not a single person I can find tweeted LockBit has a Mac targeting version before I did above yesterday, nor can find any blog posts mentioning it, etc. So even if the gang had the first build in 2022 November, for public, this is not late at all, but even yet, seems the first… pic.twitter.com/4iR71cuLpo
— MalwareHunterTeam (@malwrhunterteam) April 16, 2023
Regardless, MalwareHunterTeam believes this is the first public alert about LockBit tracking Apple devices. With the group’s RaaS approach, we’re likely to see another wave of ransomware attacks targeting Macs.
Source: KOCPC Chinese