New EvilQuest ransomware discovered targeting macOS users

silversurfer

Super Moderator
Thread author
Verified
Top Poster
Staff Member
Malware Hunter
Aug 17, 2014
11,126
Security researchers have discovered this week a new ransomware strain targeting macOS users.

Named OSX.EvilQuest, this ransomware is different from previous macOS ransomware threats because besides encrypting the victim's files, EvilQuest also installs a keylogger, a reverse shell, and steals cryptocurrency wallet-related files from infected hosts.

"Armed with these capabilities, the attacker can main full control over an infected host," said Patrick Wardle, Principal Security Researcher at Jamf. This means that even if victims paid, the attacker would still have access to their computer and continue to steal files and keyboard strokes. Wardle is currently one of the many macOS security researchers who are analyzing this new threat.

Others who are also investigating EvilQuest include Thomas Reed, Director of Mac & Mobile at Malwarebytes, and Phil Stokes, macOS security researcher at SentinelOne. Reed and Stokes are currently looking for a weakness or bug in the ransomware's encryption scheme that could be exploited to create a decryptor and help infected victims recover their files without paying the ransom.

But the researcher who first spotted the new EvilQuest ransomware is K7 Lab security researcher Dinesh Devadoss. Devadoss tweeted about his finding yesterday, June 29. However, new evidence surfaced in the meantime has revealed that EvilQuest has been, in reality, distributed in the wild since the start of June 2020.
 

silversurfer

Super Moderator
Thread author
Verified
Top Poster
Staff Member
Malware Hunter
Aug 17, 2014
11,126

Ink

Administrator
Verified
Jan 8, 2011
22,490
Apple adds detection to XProtect.

On 13 July Apple shipped a new version of XProtect, now version 2126. This version came just a week after version in 2125, which is unusual for Xprotect. Normally updates are released every other week, or least that has been the case through the past six months.

Apple doesn’t make it easy to see what has changed but Electric Light notes a new entry named MACOS.2070d41 among XProtect’s Yara definitions as well as some modifications to MACOS.6cb9746, which apparently detects ThiefQuest/EvilQuest and prevents installation.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top