VORANT. Threat Intelligence Sign in Get the full feed

OSX.EvilQuest ransomware spreads via pirated Mac apps

medium threat

A new macOS ransomware, OSX.EvilQuest, is bundled in trojanized pirated software on torrent sites and combines encryption with anti-analysis, keylogging and persistence features.

Researchers identified a new macOS ransomware family, dubbed OSX.EvilQuest, being distributed inside trojanized installers for pirated software (observed in a fake 'Mixed In Key 8' DMG). The malicious postinstall script drops an unsigned Mach-O binary ('patch', later renamed 'toolroomd') that requests root during installation and persists itself as a LaunchDaemon/LaunchAgent disguised as an Apple process (com.apple.questd).

Analysis of the binary revealed extensive anti-analysis tradecraft: sandbox/VM detection via sleep-patching checks, anti-debugging via sysctl P_TRACED checks and ptrace(PTRACE_DENY_ATTACH), and string obfuscation/encryption requiring dynamic library injection to decrypt. Beyond file encryption for ransom (demanding ~$50 in Bitcoin with a 72-hour deadline), the sample contains capabilities well beyond typical ransomware, including keylogging (CGEventTap APIs), host/process reconnaissance, in-memory code execution, and logic to search for and exfiltrate sensitive files such as SSH keys, certificates, and cryptocurrency wallet images. It also attempts to kill security tools including Little Snitch, Kaspersky, Norton, Avast, DrWeb, McAfee, Bitdefender and BullGuard before persisting.

Decrypted strings exposed a hardcoded C2 domain and IP address. At time of analysis the malicious DMG and payload were undetected by VirusTotal AV engines, though detection was expected to improve. The infection vector — pirated software shared via torrents — is unsophisticated but has proven a persistently effective distribution method for macOS malware such as OSX/Shlayer.

Mentioned in this report

Malware OSX.EvilQuest

Source reporting: https://objective-see.org/blog/blog_0x59.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free