Last week one of my clients contracted Crypto Locker in their Windows VM.
The malware entered via an attachment in Apple Mail as a ZIP archive that contained a Windows executable (.exe). Long story short, it got double-clicked and proceeded to encrypt the documents on their server's shared drive, which was mounted on the Mac side of the computer and shared via the Parallels Shared Folders.
We had solid backups, so we deleted the infected VM and restored from backup, but many of their files were encrypted by the malware and hence unusable.
This was a first for me: damage to Macintosh files from the virtual machine. Since then I have limited which folders can be accessed by the virtual machine and turned off coherence mode. I welcome other suggestions.
Rob
The malware entered via an attachment in Apple Mail as a ZIP archive that contained a Windows executable (.exe). Long story short, it got double-clicked and proceeded to encrypt the documents on their server's shared drive, which was mounted on the Mac side of the computer and shared via the Parallels Shared Folders.
We had solid backups, so we deleted the infected VM and restored from backup, but many of their files were encrypted by the malware and hence unusable.
This was a first for me: damage to Macintosh files from the virtual machine. Since then I have limited which folders can be accessed by the virtual machine and turned off coherence mode. I welcome other suggestions.
Rob