HomeSecurityEvilQuest uses ransomware as a cover to steal files from...

EvilQuest uses ransomware as a cover to steal files from Macs

A new data-scavenging and information-stealing program called EvilQuest uses ransomware as bait to steal files from Macs. Victims are infected after downloading trojanized installers of popular applications from torrent trackers.

While not common, ransomware has been known to target the macOS platform in the past, with KeRanger, FileCoder (aka Findzip), and Patcher being three other examples of malware designed to encrypt Mac systems.

EvilQuest was first discovered by K7 Lab malware researcher Dinesh Devadoss and analyzed by Malwarebytes' Mac & Mobile Director Thomas Reed, Jamf Principal Researcher Patrick Wardle, and BleepingComputer's Lawrence Abrams.

EvilQuest ransomware Mac

Installs a keylogger and opens a "reverse shell"

Devadoss discovered that EvilQuest includes the ability to check if it is running in a virtual machine and has debugging capabilities.

It also checks some common security tools (Little Snitch) and antimalware solutions (Kaspersky, Norton, Avast, DrWeb, Mcaffee, Bitdefender and Bullguard) and opens a "reverse shell" used to communicate with the command-and-control (C2) server as discovered by Felix Seele.

The malware will connect to http://andrewka6.pythonanywhere[.]com/ret.txt to obtain the IP address of the C2 server to download further files and send data.

As Reed found after examining the ransomware, EvilQuest is delivered using infected installers.

Although .PKG installers downloaded from popular torrent sites look like any legitimate installer when launched, they are distributed as DMG files and lack a custom icon which is a warning sign that something is not right for many macOS users.

Reed also found that, in the case of one of the EvilQuest samples analyzed, the packages of the compressed installer files included the original installers and uninstallers of the pirated applications, along with a malicious binary patch and a script used to launch the installer and launch the malware.

After gaining persistence on the infected device, EvilQuest launches a formatted copy of itself and begins encrypting files that add a BEBABEDD marker to the end.

Unlike Windows ransomware, EvilQuest has problems that start when it encrypts files. When it does, it is not selective.

It appears to lock files randomly, creating various issues on the compromised system from encrypting the “login keychain” to resetting the Dock to its default appearance and causing the Finder to freeze.

EvilQuest uses ransomware as a cover to steal files from Macs

“Once file encryption is complete, it creates a text file named READ_ME_NOW.txt with ransom instructions,” Wardle added.

Victims are asked to pay a ransom of $50 in bitcoin within three days (72 hours) to recover encrypted files .

EvilQuest uses ransomware as a cover to steal files from Macs

EvilQuest uses the same static Bitcoin for all victims and does not include an email for contact after payment is made.

This makes it impossible for attackers to track down victims who paid the ransom and for a victim to contact the ransomware operators for a decryptor.

Wipers, however, are usually used as a cover for some other malicious activity.

Malicious cleaning software used for data theft

After analyzing the malware, we believe that the ransomware is simply a decoy for the real purpose of this malware.

That is, to search for and steal certain types of files from the infected computer.

When the malware runs on a Mac, it will execute shell commands that download Python dependencies, Python scripts disguised as GIF , and then execute them.

The tasks executed with the above command are:

  • Delete the files /Users/user1/client/exec.command and /Users/user1/client/click.js.
  • Download and install PIP
  • Installing Python requests
  • Download p.gif, which is a Python file, and run it.
  • Download pct.gif, which is another Python file, and run it.

The p.gif file is a very obscure Python script and we were unable to determine what functionality .

What should victims do?

As you can see, the EvilQuest wiper is much more harmful than first thought, as not only will the data be encrypted, but it may not be decrypted even if the victim pays.

To make matters worse, the malware will steal files from your computer that contain sensitive information that could be used for various malicious purposes, such as identity theft, password , and theft of private keys and security certificates.

If your Mac was infected with this malware, you should assume that any files matching the listed extensions have been stolen or compromised in some way.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS