A reverse-engineering analysis found that an apparent wave of more than 40,000 daily macOS malware samples was not a broad new outbreak but a VirusTotal sandbox feedback loop caused by a self-mutating EvilQuest/ThiefQuest variant. The malware repeatedly opened its own file via argv[0], located the Mach-O __cstring section, and rewrote obfuscated strings on disk after decrypting and re-encrypting them. As a result, each execution produced a slightly different binary with the same __text hash but altered string data, leading VirusTotal to classify and resubmit each mutated copy as a new sample. The activity was traced back to initial submissions from Germany, and the analyzed variant was identified as an actively developed build linked to the hardcoded C2 address 159.65.147.28.
The research concluded that the surge exposed a weakness in macOS sandbox handling for self-modifying binaries and risked wasting analysis capacity and storage. Early antivirus detection for the malware was low before improving as signatures were updated. Supporting that analysis, a public GitHub repository released shortly afterward provided a Go-based EvilQuest/ThiefQuest string deobfuscation tool designed to decrypt individual or bulk-obfuscated strings from samples, building on the reverse-engineering work and earlier community tooling to aid further malware analysis.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository for an EvilQuest/ThiefQuest strings decryptor and deobfuscator by Pedro Vilaça was published with usage for decrypting a single string or all strings in a file. The repository referenced the prior day's "EvilQuest revisited" analysis and Scott Knight's earlier Python implementation.
Pedro Vilaça published findings that the apparent flood of more than 40,000 daily macOS malware samples was not a massive campaign but a VirusTotal macOS sandbox feedback loop triggered by a new EvilQuest/ThiefQuest variant. He showed the binaries shared identical code sections while mutating encrypted strings on disk between executions.
Daily sample counts on VirusTotal rose sharply beginning on September 5 as the malware repeatedly rewrote its own __cstring section and was resubmitted as new binaries. The article cites 47,782 samples on September 6 and similar volumes on subsequent days.
Two likely patient-zero EvilQuest/ThiefQuest samples were first seen on VirusTotal under the submission name "ookcucythguan," uploaded from Germany. These submissions appear to have started the later chain of self-mutating samples.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 37 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.