Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware ThiefQuest

ThiefQuest

TLP:CLEAR
Family

Also known as: MacRansom.K, EvilQuest

AI Analysis

· 1 day ago

Executive Summary

ThiefQuest is a macOS‑specific wiper that pretends to be ransomware but never sends decryption keys, leading to permanent data loss. It also steals user credentials from browsers and system caches before performing destructive operations. The malware spreads through trojanized pirated apps shared on Russian forums.

Enhanced Description

ThiefQuest, also known as MacRansom.K or EvilQuest, is a malicious macOS‑only threat that masquerades as ransomware but functions more accurately as a destructive wiper combined with basic credential theft. The package first surfaced in 2020 behind trojanized copies of popular macOS applications that were shared on Russian torrent and forum sites. When executed the payload claims to encrypt user data, displays a forged ransom note, yet never transmits an encryption key to any command‑and‑control infrastructure – the generated keys exist solely on the infected host. Beyond its surface ransomware veneer, ThiefQuest actively scans for sensitive artifacts such as login credentials stored in browsers and system caches. It then attempts to delete or overwrite protected user files, causing irreversible data loss. Because the malware does not rely on external key exchange, attackers have no method to recover the encrypted contents; this indicates the intent is to disrupt rather than profit from encryption fees. The binary utilizes basic macOS process injection and sandbox bypass techniques, enabling it to persist in memory long enough to complete file deletion operations. It also embeds a minimal set of obfuscation routines to thwart static analysis. Although the threat has not been widely reported beyond early 2020 samples, its distribution vector indicates that adversaries still employ pirated software as a low‑cost propagation method targeting uninformed macOS users. Overall, ThiefQuest exemplifies the hybrid strategy of modern wiper ransomware variants: presenting a ransom facade to scare victims while ensuring irreversible damage to data assets. Its combination of credential harvesting and destructive file manipulation amplifies both the human and operational impact on compromised organizations.

Key Capabilities

  • Disguises itself as ransomware
  • Generates but does not transmit encryption keys
  • Deletes or overwrites user files (wiper behavior)
  • Collects stored browser credentials
  • Uses basic macOS process injection for persistence
  • Obfuscates code to evade static analysis

ATT&CK Techniques

T1485
T1490
T1041

Recommended Actions

  • Block download and execution of trojanized macOS applications from untrusted sources
  • Implement App Sandbox policies limiting file system access
  • Deploy EDR/anti‑malware solutions that flag file deletion activity on macOS
  • Apply regular backups and enable versioning to mitigate wiper impact
  • Educate users about the risks of downloading software from torrent sites

Suggested Tags

macOS
wiper
ransomware-like
credential theft
trojanized software
Russian forum distribution

Confidence Assessment

Confidence in the basic description of ThiefQuest’s behavior is moderate, based on published analysis reports. However, detailed information on persistence mechanisms, command‑and‑control channels, and recent activity is limited; further forensic investigation would refine detection signatures and mitigation strategies.

Description

ThiefQuest is a virus, data stealer, and wiper that presents itself as ransomware targeting macOS systems. ThiefQuest was first seen in 2020 distributed via trojanized pirated versions of popular macOS software on Russian forums sharing torrent links.(Citation: Reed thiefquest fake ransom) Even though ThiefQuest presents itself as ransomware, since the dynamically generated encryption key is never sent to the attacker it may be more appropriately thought of as a form of wiper malware.(Citation: wardle evilquest partii)(Citation: reed thiefquest ransomware analysis)

Details

Type
Malware
Platforms
Macos
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.