ThiefQuest, also known as EvilQuest and MacRansomK, is a macOS malware family that emerged in 2020 and is best characterized as an infostealer/backdoor that uses ransomware-like behavior as a decoy. It has been distributed through trojanized installers of pirated macOS applications, including repackaged DMG installers, and targets macOS users. Although initially publicized as ransomware, subsequent analysis showed its encryption routine was unreliable and likely secondary to data theft and broader post-compromise activity.
On execution, ThiefQuest establishes persistence by copying itself into a user Library location under a hidden or disguised name and installing a LaunchAgent configured to run the persistent binary at login. It also hides artifacts using dot-prefixed filenames. The malware performs local discovery, including process enumeration, and checks for security and analysis tools. It contains anti-analysis logic, including debugger and virtual-machine or sandbox-evasion checks, and can terminate processes associated with security software.
ThiefQuest has backdoor functionality, including opening a reverse shell and communicating with command-and-control infrastructure over HTTP. It downloads and executes additional Python-based payloads, one of which has been used to search user directories for files matching targeted extensions associated with documents, certificates, source code, archives, databases, presentations, spreadsheets, images, and cryptocurrency wallets. Matching files are exfiltrated to attacker-controlled infrastructure, with observed transfers occurring over unencrypted HTTP.
A notable propagation and persistence-related behavior is its modification of executable files on disk: ThiefQuest searches user-accessible locations for executables, prepends its own code to them, preserves apparent normal execution by launching a hidden copy of the original program, and thereby ensures its code runs first when the trojanized executable is launched. This behavior combines defense evasion, persistence, and post-exploitation tradecraft.
The ransomware component encrypts files and presents a ransom demand, but the implementation has been assessed as ineffective and potentially destructive, with behavior more consistent with a wiper-like decoy than a mature extortion operation. Reported side effects included damage to normal system functionality. Overall, ThiefQuest is a macOS threat that blends persistence, anti-analysis, security-tool interference, reverse-shell access, file theft, and deceptive ransomware behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
ThiefQuest also copies itself into ~/Library/AppQuest/com.apple.questd and creates a launch agent property list at ~/Library/LaunchAgents/com.apple.questd.plist with a RunAtLoad key set to true to automatically get launched whenever the victim logs into the system.
It also checks for some common security tools ... and opens a reverse shell used for communication with its command-and-control (C2) server. | When the malware is executed on a Mac, it will execute shell commands that download Python dependencies, Python scripts disguised as GIF files, and then run them.
In the next part of our series, we’re going to start looking at one of the major challenges in reversing macOS malware that you are bound to face on a regular basis: dealing with encrypted and obfuscated strings
At the entrypoint we can observe the mutation function being called first with argv[0] as its argument... call fg_open_and_reencrypt_cstrings ; binary self modifies here... The function will find the __cstring section and iterate over its contents, decrypting and encrypting the strings, and write back to the binary.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
In fact, it looks like an attempt to evade automated sandboxes that patch the sleep function, and we’re not likely to fall foul of it just by executing in our VM.
It seems this function subtracts the sleep interval from the second timestamp, then compares it against the first timestamp... In fact, it looks like an attempt to evade automated sandboxes that patch the sleep function
The content repeatedly describes malware and threat actors creating hidden folders, adding dot prefixes to filenames, and setting file attributes such as hidden/system to conceal files and directories from users and defenders.
"Brute Ratel C4 has used reflective loading to execute malicious DLLs." / "Cobalt Strike's execute-assembly command can run a .NET executable within the memory of a sacrificial process..." / "FoggyWeb's loader has reflectively loaded .NET-based assembly/payloads into memory."
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
When executed, this script will search for any files under the /Users folder that contain the following extensions .pdf, .doc, .jpg, .txt ... .wallet, .dat
In fact, it looks like an attempt to evade automated sandboxes that patch the sleep function, and we’re not likely to fall foul of it just by executing in our VM.
It seems this function subtracts the sleep interval from the second timestamp, then compares it against the first timestamp... In fact, it looks like an attempt to evade automated sandboxes that patch the sleep function
It also checks for some common security tools (Little Snitch) and antimalware solutions (Kaspersky, Norton, Avast, DrWeb, Mcaffee, Bitdefender, and Bullguard).
The pct.gif file is not obfuscated and is clearly a data exfiltration script that steals files under the /Users folder and sends it to a remote URL.
Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP... Tomiris can upload files matching a hardcoded set of extensions... PowerShower packed and exfiltrated .txt, .pdf, .xls or .doc files smaller than 5MB modified during the past two days.
The malware will connect to http://andrewka6.pythonanywhere[.]com/ret.txt to get the IP address of the C2 server to download further files and send data.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes threat actors and malware disabling, stopping, uninstalling, or modifying antivirus, EDR, Windows Defender, AMSI, logging, and other security controls.
Examples include 'Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools', 'BlackByte disabled security tools such as Windows Defender', 'Scattered Spider has uninstalled and disabled security tools', and many malware families terminating AV/EDR processes or services.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS ransomware that combines file encryption with data theft.
Software changes: ... ThiefQuest
Ransomware that exfiltrates targeted files from /Users/ to its C2 server via unencrypted HTTP.
Ransomware that uses APIs for payload execution and local enumeration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.