VORANT. Threat Intelligence Sign in Get the full feed

OSX.EvilQuest macOS malware doubles as file infector

medium threat

Deep analysis reveals OSX.EvilQuest is a true self-replicating macOS virus combining ransomware, keylogging, remote tasking, and credential/wallet theft.

Objective-See's follow-up analysis of OSX.EvilQuest shows the macOS malware is far more than commodity ransomware. It contains genuine viral infection logic — recursively scanning user directories, prepending itself to legitimate executable Mach-O binaries, and restoring the original binary's bytes from an appended trailer so infections remain unnoticed while propagating locally. This self-replicating behavior means simple removal of the malware's launch items is insufficient; the authors recommend a full OS reinstall for infected hosts.

Beyond infection, EvilQuest runs a forensic-exfiltration thread that harvests directory listings and searches for sensitive files (SSH keys, certificates, .pem/.p12/.pfx files, and cryptocurrency wallet images) under 7KB, sending matches to a remote C2 server resolved via a hardcoded pythonanywhere.com dropper page or a fallback hardcoded IP. The malware supports a compact remote tasking protocol allowing in-memory payload execution, file drop/execute, keylogging via CGEventTap, arbitrary shell command execution via popen, and includes a kqueue-based self-healing persistence mechanism that automatically restores its on-disk binary and LaunchDaemon/LaunchAgent artifacts if tampered with.

The ransomware component encrypts a broad list of file extensions after a delay, dropping a ransom note (READ_ME_NOW.txt) and using macOS's 'say' command to read it aloud. Notably, researchers found the malware contains a decryption routine (uncarve_target) that is never actually called, and the generated encryption key is never transmitted to the C2 server — strongly suggesting that victims who pay have no functional path to recovering their files. Objective-See's free tools BlockBlock and RansomWhere? reportedly detected and blocked key stages of the attack without prior signature knowledge.

Mentioned in this report

Malware OSX.EvilQuest

Source reporting: https://objective-see.org/blog/blog_0x60.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free