Summary:
The LockBit ransomware group has developed encryptors exclusively for Macs for the first time, making it possibly the first significant ransomware operation to ever target macOS. A researcher who uncovered a ZIP archive containing what appeared to be the majority of the LockBit encryptors that were available also found the new ransomware encryptors. Encryptors created for attacks on Windows, Linux, and VMware ESXi servers are used by the LockBit operation.[/subscribe_to_unlock_form]
Summary:
The LockBit ransomware group has developed encryptors exclusively for Macs for the first time, making it possibly the first significant ransomware operation to ever target macOS. A researcher who uncovered a ZIP archive containing what appeared to be the majority of the LockBit encryptors that were available also found the new ransomware encryptors. Encryptors created for attacks on Windows, Linux, and VMware ESXi servers are used by the LockBit operation.[emaillocker id="1283"]
Strings found in the LockBit encryptor for Apple M1 suggest that they were randomly put together in a test, as they don't belong in a macOS .There is a list of 65 filenames and file extensions in the encryptor that will not be encrypted they are all Windows filenames and folders. The MIPs and FreeBSD encryptors contain almost all of the ESXi and Windows strings, proving that they share the same codebase. It appears that macOS is now on their radar but this is still far from being ready for deployment aside from compiling it for macOS and adding a basic config. Wardle added that the developer of LockBit must first figure out how to bypass TCC, and get notarized in order to become a useful encryption tool.
There is no obstacle preventing developers from making malware that targets Macs, even though Windows has been the most frequently targeted operating system in ransomware attacks. the LockBit operation is known for pushing the limits of ransomware development, it would not be unexpected to see more sophisticated and optimised encryptors for these CPU architectures released in the future. All computer users, including those who own Macs, should adopt good internet safety practises, such as keeping the operating system updated, staying away from executable attachments, creating offline backups, and using strong and different passwords on every website you visit.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]