Ransomware attacks don't just target Windows systems, they also threaten MacOS , encrypting files and demanding a ransom to access a decryption tool. One such ransomware targeting Mac computers is EvilQuest .

Researchers from the Microsoft Security Threat Intelligence have identified multiple ransomware attacks on Apple.
Very often, users are tricked into giving cybercriminals access to their systems by opening malicious emails or downloading and running documents or programs containing ransomware.
See also: Cyberattacks increased by 38% in 2022
The ransomware can also reach the device as a second-stage payload that is installed via other malicious software that has previously infected the machine.
Researchers warn that the increased attacks on MacOS show that ransomware is a significant risk for all operating systems.
"Ransomware continues to be one of the most widespread and dangerous threats affecting organizations, with attackers constantly evolving their techniques and expanding their reach to target more users," Microsoft said in a post.
“While these malware families are old, they exemplify the range of capabilities and malicious behavior possible on the platform,” they added.
As with ransomware targeting other operating systems, ransomware targeting MacOS is equipped with features designed to achieve persistence and evade detection until it is too late.
See also: Research: Hackers use ChatGPT
These capabilities include delaying the execution of the malware to avoid detection in the early stages of the attack, instructions to execute every time the machine boots, and using legitimate functions in MacOS to execute commands and spread the attack.
One of the most dangerous ransomware targeting Mac is EvilQuest. This ransomware first appeared in 2020 and continues to target Mac systems to this day.
According to Microsoft, newer versions of EvilQuest ransomware have additional capabilities (beyond encryption) including keylogging, which informs criminals about victims' keystrokes. This feature is useful because it reveals usernames, passwords, and other sensitive data to attackers .

EvilQuest is also capable of software security to avoid detection.
Other forms of Mac ransomware detailed by Microsoft include KeRanger, FileCoder, and MacRansom. All of them use techniques designed to make detection difficult for users or cybersecurity teams.
Microsoft says it has detailed information about Mac ransomware to help defend against attacks.
“Ransomware continues to be one of the most significant threats affecting any platform. Our analysis of ransomware on Mac operating systems shows how its creators use various techniques to hide from automated analysis systems,” the company said.
See also: Fake Pokemon NFT game installer allows hijacking of your PC
“Understanding ransomware routines and their impacts on any device or platform is essential for individual users in order to take measures to protect devices and data“.
Some of the tips on how to avoid falling victim to ransomware include installing applications from trusted sources, restricting access to important resources if users don't need them, regularly updating operating systems and programs, using antivirus programs, and creating backups.
And regardless of the operating system used, organizations should help employees understand the risks.
Source: www.zdnet.com
