New Mac Ransomware Found in Pirated Mac Apps

There's a new 'EvilQuest' Mac ransomware variant that's spreading through pirated Mac apps, according to a new report shared today by Malwarebytes. The new ransomware was found in pirated download for the Little Snitch app found on a Russian forum.

evilquestransomalert
Right from the point of download, it was clear that something was wrong with the illicit version of Little Snitch, as it had a generic installer package. It installed the actual version of Little Snitch, but it also installed an executable file named "Patch" into the /Users/Shared directory and a post-install script for infecting a machine.

The installation script moves the Patch file into a new location and renames it CrashReporter, a legitimate macOS process, keeping it hidden in Activity Monitor. From there, the Patch file installs itself in several spots on the Mac.

The ransomware encrypts settings and data files on the Mac, like Keychain files, resulting in an error when attempting to access the iCloud Keychain. The Finder also malfunctioned after installation, and there were problems with the dock and other apps.

Malwarebytes found the ransomware to work poorly and was not able to get instructions on paying the ransom, but a screenshot found on the forums where the malicious software originated suggests it's meant to prompt users to pay $50 to recover access to their files. Note: anyone infected with this ransomware or any ransomware should not pay the fee, because it does not remove the malware.

Along with the ransom activity, the malware may also install a keylogger for monitoring keystrokes, but what the malware does with the functionality is unknown. Malwarebytes says that its software for Mac is able to remove the ransomware, detected as Ransom.OSX.EvilQuest. Encrypted files will require a restore from a backup, though.

Similar ransomware was found in other pirated apps, and Mac users can avoid it by staying away from pirated apps and untrustworthy websites and forums that offer illicit downloads.

Top Rated Comments

Apple Macintosh 128K Avatar
51 months ago
Stick to legit apps from legit services and you'll be fine. Also keep an eye to make sure the apps are properly signed.

To have this happen you have to bypass macOS security and allow the non-signed installer run. It's like giving the keys to your house to some questionable person on the street and then being surprised when they take your stuff.
Score: 30 Votes (Like | Disagree)
icanhazmac Avatar
51 months ago
While more ransomware on Macs is not welcome pirates get what pirates get.
Score: 25 Votes (Like | Disagree)
swm Avatar
51 months ago
in any case, if this happens to you, a 2 step procedure will save the day:
- boot into internet recovery (can't be sure if the on-disk recovery data is compromised)
- reinstall from timecapsule
Score: 17 Votes (Like | Disagree)
Mr_Brightside_@ Avatar
51 months ago

Not to worry, this is what developers want apparently, rather than paying 30% to Apple.
I'm not sure you understand the situation fully...
Score: 17 Votes (Like | Disagree)
doboy Avatar
51 months ago
That's what you get for pirating apps.
Score: 16 Votes (Like | Disagree)
neoelectronaut Avatar
51 months ago
No sympathy for anyone that pirates software.
Score: 13 Votes (Like | Disagree)

Popular Stories

apple crush ad

Apple Apologizes for 'Crush' iPad Pro Ad, Won't Put It on TV

Friday May 10, 2024 8:32 am PDT by
When introducing the new M4 iPad Pro models, Apple showed a video of a hydraulic press crushing all manner of creative tools, including musical instruments, electronic equipment, arcade games, paint and brushes, computers, cameras, and more, with the aim of demonstrating how the iPad represents all of the tools condensed into a single device. The ad was a play on the popular hydraulic press...
ChatGPT for Mac

OpenAI Announces ChatGPT App for Mac, GPT-4 for Free, and More

Monday May 13, 2024 10:43 am PDT by
At its Spring Update event, OpenAI announced that it will be releasing a desktop app for the Mac, as seen in the screenshot below. The app will be rolling out to ChatGPT Plus subscribers starting today, ahead of a wider launch "in the coming weeks." "With a simple keyboard shortcut (Option + Space), you can instantly ask ChatGPT a question," OpenAI's press release says. In addition, Voice...
Beyond iPhone 13 Better Blue Face ID Single Camera Hole

10 Reasons to Wait for Next Year's iPhone 17

Thursday May 9, 2024 9:00 am PDT by
Apple's iPhone development roadmap runs several years into the future and the company is continually working with suppliers on several successive iPhone models concurrently, which is why we sometimes get rumored feature leaks so far ahead of launch. The iPhone 17 series is no different, and already we have some idea of what to expect from Apple's 2025 smartphone lineup. If you plan to skip...
iOS 17

Apple Releases iOS 17.5 With Cross-Platform Tracking Detection, EU App Downloads From Websites and More

Monday May 13, 2024 10:04 am PDT by
Apple today released iOS 17.5 and iPadOS 17.5, major updates to the iOS 17 and iPadOS 17 operating system updates that came out last September. The 17.5 updates come more than two months after the launch of iOS 17.4 and iPadOS 17.4. iOS 17.5 and iPadOS 17.5 can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update. In the European Union, ...
apple tv 4k red image

Apple Releases tvOS 17.5

Monday May 13, 2024 10:01 am PDT by
Apple today released tvOS 17.5, the fifth update update to the tvOS 17 operating system that came out last September. tvOS 17.5 comes two months after the release of tvOS 17.4. tvOS 17.5 can be downloaded using the Settings app on the ‌Apple TV‌. Go to System > Software Update to get the new software. ‌Apple TV‌ owners who have automatic software updates activated will be upgraded to ...
macos sonoma 4

Apple Releases macOS Sonoma 14.5 With Apple News+ Improvements

Monday May 13, 2024 10:04 am PDT by
Apple today released macOS Sonoma 14.5, the fifth update to the macOS Sonoma operating system that launched last September. macOS Sonoma 14.5 comes more than two months after the launch of macOS Sonoma 14.4. The ‌‌‌‌‌macOS Sonoma‌‌‌ 14.5 update can be downloaded for free on all eligible Macs using the Software Update section of System Settings. There's also a macOS 13.6.7...