EvilQuest (aka ThiefQuest) is a ransomware variant that targets macOS systems. EvilQuest also includes some information-stealing and data exfiltration features. It is actively being enhanced with new features to avoid detection.
Symptoms
You might observe the following artifacts associated with this threat:
- Files rendered inaccessible with altered extensions.
- Presence of a ransom note demanding payment for file decryption.
- Unexpected system behavior, such as frequent crashes or degraded performance.
- Unauthorized network activity indicating potential data exfiltration.
Technical Breakdown
Upon execution, the malware performs the following actions:
- Persistence Mechanism: Installs itself as a launch item, ensuring execution upon subsequent user logins.
- File Encryption: Encrypts system files and displays a ransom note demanding payment for decryption.
- Data Exfiltration: Scans the system for sensitive information, including certificates, keys, and cryptocurrency wallets, and transmits them to the attacker's server.
- Remote Control Capabilities: Allows attackers to execute arbitrary scripts, log keystrokes, and exfiltrate additional data.
Notably, EvilQuest's ransomware functionality may serve as a decoy, with its primary objective being data theft and establishing persistent remote access.
Next Steps
Iru Endpoint Detection & Response (EDR) automatically removes detected threats when file monitoring is set to Protect.
While the malicious file is removed, it can leave behind artifacts that need to be cleaned manually.
In the future, avoid downloading and installing software from torrent sources or untrusted websites. Ensure that all applications are obtained from official and reputable sources to maintain system integrity and security.
Poseidon
Poseidon (RodrigoStealer) is an information stealer targeting macOS users, masquerading as legitimate applications such as the Arc browser. It is designed to exfiltrate sensitive data, including system information, browser credentials, cryptocurrency wallets, and documents. It has been associated with Russian-speaking cybercriminal communities and is actively distributed through phishing campaigns and compromised websites.
Learn MoreProcessHub Stealer
ProcessHub stealer is a relatively new finding attributed to China, and is designed to collect user files including bash history, zsh history, GitHub configuration, SSH information, and the Keychain. It completes these actions in a multi-stage process including the downloading of a script from its command and control server, the collection of user files, and the uploading these files.
Learn MoreAdload
Adload is a family of adware that infects macOS systems by masquerading as legitimate software requesting user permissions. Once installed, Adload directs users to unwanted ads, changes browser settings, and can significantly slow the performance of your computer. In addition to this, Adload puts your privacy at risk by tracking your online activity and installing other harmful programs without user permissions. Adload is sometimes dropped by macOS malware Shlayer.
Learn More