# OSX.EvilQuest ransomware spreads via pirated Mac apps

Published: 2020-06-29 · Severity: medium
Canonical: https://vorant.io/reports/9eca354c-8b15-5cd5-b8e0-74ec244d41ea/osx-evilquest-ransomware-spreads-via-pirated-mac-apps

> A new macOS ransomware, OSX.EvilQuest, is bundled in trojanized pirated software on torrent sites and combines encryption with anti-analysis, keylogging and persistence features.

Researchers identified a new macOS ransomware family, dubbed OSX.EvilQuest, being distributed inside trojanized installers for pirated software (observed in a fake 'Mixed In Key 8' DMG). The malicious postinstall script drops an unsigned Mach-O binary ('patch', later renamed 'toolroomd') that requests root during installation and persists itself as a LaunchDaemon/LaunchAgent disguised as an Apple process (com.apple.questd).

Analysis of the binary revealed extensive anti-analysis tradecraft: sandbox/VM detection via sleep-patching checks, anti-debugging via sysctl P_TRACED checks and ptrace(PTRACE_DENY_ATTACH), and string obfuscation/encryption requiring dynamic library injection to decrypt. Beyond file encryption for ransom (demanding ~$50 in Bitcoin with a 72-hour deadline), the sample contains capabilities well beyond typical ransomware, including keylogging (CGEventTap APIs), host/process reconnaissance, in-memory code execution, and logic to search for and exfiltrate sensitive files such as SSH keys, certificates, and cryptocurrency wallet images. It also attempts to kill security tools including Little Snitch, Kaspersky, Norton, Avast, DrWeb, McAfee, Bitdefender and BullGuard before persisting.

Decrypted strings exposed a hardcoded C2 domain and IP address. At time of analysis the malicious DMG and payload were undetected by VirusTotal AV engines, though detection was expected to improve. The infection vector — pirated software shared via torrents — is unsophisticated but has proven a persistently effective distribution method for macOS malware such as OSX/Shlayer.

## Mentioned in this report

- Malware: OSX.EvilQuest

Source reporting: https://objective-see.org/blog/blog_0x59.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9eca354c-8b15-5cd5-b8e0-74ec244d41ea/osx-evilquest-ransomware-spreads-via-pirated-mac-apps.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
