ThiefQuest
MITRE ATT&CK: S0595 View on attack.mitre.org
Aliases: MacRansom.K, EvilQuest, ThiefQuest
- First seen
- 2020-01-01 00:00:00
- Malware type
- virus, wiper, trojan, ransomware
- Family
- Malware family
- Operating systems
- macos
- Related IoCs
- 47 (47 malicious)
- Last IoC activity
- 2026-08-29 21:01:10
- Profile updated
- 2026-07-07 14:22:14
Targeted regions: country_code:ru
Context
ThiefQuest is a virus, data stealer, and wiper that presents itself as ransomware targeting macOS systems. ThiefQuest was first seen in 2020 distributed via trojanized pirated versions of popular macOS software on Russian forums sharing torrent links. Even though ThiefQuest presents itself as ransomware, since the dynamically generated encryption key is never sent to the attacker it may be more appropriately thought of as a form of wiper malware.
Recent IoC activity
47 malicious indicators in Maltiverse are attributed to ThiefQuest (S0595). The 20 most recently updated:
Detection coverage
- 336 Sigma rules
Malware & tools used
- Data Encrypted for Impact (attack-pattern)
- Web Protocols (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Keylogging (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Compromise Host Software Binary (attack-pattern)
- Launch Daemon (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- AppleScript (attack-pattern)
- Launch Agent (attack-pattern)
- Process Discovery (attack-pattern)
- Reflective Code Loading (attack-pattern)
- Security Software Discovery (attack-pattern)
- Native API (attack-pattern)
- Time Based Checks (attack-pattern)
- Debugger Evasion (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
Reports & references
- blackberry.com — Report Bb 2021 Threat Report (report)
- objective-see.com — Blog 0X5F (report)
- malpedia.caad.fkie.fraunhofer.de — Osx.Evilquest (report)
- github.com — Evilquest Deobfuscator (report)
- sentinelone.com — Defeating Macos Malware Anti Analysis Tricks With Radare2 (report)
- CrowdStrike — How Crowdstrike Analyzes Macos Malware To Optimize Automated Detection Capabilities (report)
- objective-see.com — Blog 0X59 (report)
- twitter.com — 1277668001538433025 (report)
- labs.sentinelone.com — Breaking Evilquest Reversing A Custom Macos Ransomware File Encryption Routine (report)
- sentinelone.com — Evilquest A New Macos Malware Rolls Ransomware Spyware And Data Theft Into One (report)
- bleepingcomputer.com — Evilquest Wiper Uses Ransomware Cover To Steal Files From Macs (report)
- MITRE ATT&CK — S0595 (report)
- blog.malwarebytes.com — Osx Thiefquest (report)
- blog.malwarebytes.com — Mac Thiefquest Malware May Not Be Ransomware After All (report)
- objective-see.com — Blog 0X60 (report)
External references
- mitre-attack — S0595
- ThiefQuest
- EvilQuest
- MacRansom.K
- wardle evilquest partii
- SentinelOne EvilQuest Ransomware Spyware 2020
- Reed thiefquest fake ransom
- reed thiefquest ransomware analysis
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy