GandCrab Ransomware

My Macbook infected Ransomware name "GandCrab". I cannot open my files in local disk and iCloud as well.

What should i do?

Posted on Feb 11, 2018 12:22 AM

Reply
Question marked as Top-ranking reply

Posted on Feb 13, 2018 7:14 PM

I've been doing research on this, and haven't found any signs of a Mac version of GandCrab yet. There are a couple possibilities.


1) You could be affected by something brand new that nobody has seen yet. If so, it'll be critically important to get as much information from you about what happened as possible.


2) If the affected disks have been accessed from a Windows machine, it's possible that the Windows machine was infected, and that resulted in encryption of files on the affected disks. This is actually the more common case to-date, as Mac ransomware has yet to be very successful.


Let us know more details so that we can identify what's going on in your case.

Similar questions

10 replies
Question marked as Top-ranking reply

Feb 13, 2018 7:14 PM in response to thomas_r.

I've been doing research on this, and haven't found any signs of a Mac version of GandCrab yet. There are a couple possibilities.


1) You could be affected by something brand new that nobody has seen yet. If so, it'll be critically important to get as much information from you about what happened as possible.


2) If the affected disks have been accessed from a Windows machine, it's possible that the Windows machine was infected, and that resulted in encryption of files on the affected disks. This is actually the more common case to-date, as Mac ransomware has yet to be very successful.


Let us know more details so that we can identify what's going on in your case.

Feb 12, 2018 1:34 PM in response to thomas_r.

I agree with Thomas. I used parallel desktop to run window. It might infected from this. Then it encrypted my files in local hard disk and the files were upload to cloud drive automaticall. Finally, the files in cloud drive are affected. I note that it encrypted with I turn on window.

First of all, I thought it didn’t change the extension of file name. So the files should be safe. But actually, I could not open the files even with macbook, iPad, iphone or safari browse. All of files are modified in the same date and time.

Fortunately, the keynote can recovery the old version of files. However, I lost all of pdf files.

Feb 14, 2018 7:54 AM in response to ninmutto-

Sounds good. If you need to run windows in something like Parallels in the future, be sure to run a good anti-virus program in the Windows system, and be cautious what folders you give that system access to on your Mac. Also, be sure you're keeping your data thoroughly backed up, if you're not already, so that if something like this happens again, you can recover easily.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

GandCrab Ransomware

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.