Views:

Supported Ransomware Families

The following list describes the known macOS ransomware-encrypted files types can be handled by the latest version of the tool.

Ransomware FamilyFile name and extension
MacRansom{original file name}

Obtaining and Executing the Tool(s)

  1. Click the Download button below to obtain the latest version of the Trend Micro Ransomware Decryptor Tool for macOS package.

    Download Ransomware Decryptor for macOS

  2. Double-click the Trend Micro Ransomware Decryptor for macOS App or drag the Trend Micro Ransomware Decryptor for macOS icon to Applications icon to install the App.

    Trend Micro Ransomware Decryptor for Mac

Step 1: Select the file or folder

On the main UI, the user can drag the file or folder from Finder window and drop the file to the center of the main UI.

Drag file or folder for decryption

The user can also click + icon and select the file or folder from the window file.

Select file or folder for decryption

Step 2: Start decrypting files

After the file(s) or folder(s) are selected, the tool will start scanning and decrypting files automatically.

Decrypting the files

By clicking the “View in Finder” button, the tool opens the decrypted file or folder location which was scanned. The decrypted file name will be {original file name}.decrypt.{extension}.

Decrypted file

Click Done to quit the tool.

MacRansom decryption only supports the following:

  • Microsoft Office documents (.docx, .xlsx, .pptx)
  • Pages documents (.pages)
  • Numbers documents (.numbers)
  • Keynote documents (.key)

Additional reference: MacRansom: Offered as Ransomware as a Service