Also known as: MacRansom.K, EvilQuest
Executive Summary
ThiefQuest is a macOS‑specific wiper that pretends to be ransomware but never sends decryption keys, leading to permanent data loss. It also steals user credentials from browsers and system caches before performing destructive operations. The malware spreads through trojanized pirated apps shared on Russian forums.
Enhanced Description
ThiefQuest, also known as MacRansom.K or EvilQuest, is a malicious macOS‑only threat that masquerades as ransomware but functions more accurately as a destructive wiper combined with basic credential theft. The package first surfaced in 2020 behind trojanized copies of popular macOS applications that were shared on Russian torrent and forum sites. When executed the payload claims to encrypt user data, displays a forged ransom note, yet never transmits an encryption key to any command‑and‑control infrastructure – the generated keys exist solely on the infected host. Beyond its surface ransomware veneer, ThiefQuest actively scans for sensitive artifacts such as login credentials stored in browsers and system caches. It then attempts to delete or overwrite protected user files, causing irreversible data loss. Because the malware does not rely on external key exchange, attackers have no method to recover the encrypted contents; this indicates the intent is to disrupt rather than profit from encryption fees. The binary utilizes basic macOS process injection and sandbox bypass techniques, enabling it to persist in memory long enough to complete file deletion operations. It also embeds a minimal set of obfuscation routines to thwart static analysis. Although the threat has not been widely reported beyond early 2020 samples, its distribution vector indicates that adversaries still employ pirated software as a low‑cost propagation method targeting uninformed macOS users. Overall, ThiefQuest exemplifies the hybrid strategy of modern wiper ransomware variants: presenting a ransom facade to scare victims while ensuring irreversible damage to data assets. Its combination of credential harvesting and destructive file manipulation amplifies both the human and operational impact on compromised organizations.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the basic description of ThiefQuest’s behavior is moderate, based on published analysis reports. However, detailed information on persistence mechanisms, command‑and‑control channels, and recent activity is limited; further forensic investigation would refine detection signatures and mitigation strategies.
ThiefQuest is a virus, data stealer, and wiper that presents itself as ransomware targeting macOS systems. ThiefQuest was first seen in 2020 distributed via trojanized pirated versions of popular macOS software on Russian forums sharing torrent links.(Citation: Reed thiefquest fake ransom) Even though ThiefQuest presents itself as ransomware, since the dynamically generated encryption key is never sent to the attacker it may be more appropriately thought of as a form of wiper malware.(Citation: wardle evilquest partii)(Citation: reed thiefquest ransomware analysis)