Multiple macOS malware campaigns used BitTorrent and pirated software installers to deliver ransomware or ransomware-themed payloads, showing that Apple systems were repeatedly targeted through fake cracks and trojanized apps. KeRanger was distributed through an infected Transmission BitTorrent client installer, while Patcher (OSX/Filecoder.E) posed as cracks for software such as Microsoft Office for Mac and Adobe Premiere Pro. Patcher encrypted files in user folders and mounted external or network volumes by placing them into password-protected ZIP archives, deleted the originals, and dropped README!.txt ransom notes demanding 0.25 BTC via a hardcoded wallet and email address.
Later analysis of EvilQuest/ThiefQuest found that its ransomware behavior was largely a cover for more destructive activity. The malware was spread through trojanized pirated macOS applications, established persistence, opened a reverse shell, checked for security tools, and downloaded Python-based payloads to steal files from /Users, including documents, certificates, source code, databases, and cryptocurrency wallets. Researchers also found major flaws in some of these campaigns: Patcher had no practical way to return encryption keys to victims even if they paid, and EvilQuest used suspiciously static ransom infrastructure, reinforcing that pirated software channels remained a recurring infection vector and that victims faced both irreversible data loss and data theft.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
BleepingComputer reported that ThiefQuest was not just ransomware but also a file stealer and wiper in disguise. The report described reverse-shell behavior, anti-analysis checks, and Python payloads used to exfiltrate sensitive files from infected Macs.
Objective-See published analysis of OSX.EvilQuest, documenting the macOS malware family. This marked public technical reporting on the threat under the EvilQuest name.
In February 2017, ESET analyzed a macOS ransomware family it detected as OSX/Filecoder.E, also calling itself "Patcher." The malware was distributed on BitTorrent sites as fake cracks for software including Microsoft Office for Mac and Adobe Premiere Pro.
A malicious recompiled Transmission 2.92 installer hosted on Transmission’s official website distributed OSX/Keydnap, an OS X backdoor that steals keychain contents and establishes persistence. Downloads obtained between August 28 and August 29, 2016 were affected, and Transmission removed the file within minutes after ESET notified the team.
Palo Alto Networks reported a new OS X ransomware family, KeRanger, distributed via an infected installer for the Transmission BitTorrent client. The reference identifies this as a distinct earlier macOS ransomware event preceding later families.
ThiefQuest was first spotted by K7 Lab researcher Dinesh Devadoss. Subsequent analysis tied the malware to trojanized installers of pirated macOS applications distributed on torrent sites.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourceobjective-see.com
Open sourcewelivesecurity.com
Open sourcewelivesecurity.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.