SentinelOne published a technical walkthrough showing how analysts can reverse the macOS malware EvilQuest and defeat its anti-analysis behavior with radare2. The guide demonstrates how to prepare a malware sample in a controlled macOS virtual machine, attach the debugger with elevated privileges, inspect functions and cross-references, and rename imported library calls to clarify the sample’s execution flow.
The tutorial focuses on dynamically bypassing EvilQuest checks without patching the binary, including skipping function execution and altering register return values during debugging. SentinelOne highlights routines such as _is_virtual_mchn and user_info, and notes that one of the checks appears closer to sleep-based sandbox evasion than true virtual-machine detection. The malware, first seen in 2020 and initially described as ransomware, is characterized in the report as ineffective in the wild and possibly a proof of concept or early-stage project.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The analyzed EvilQuest sample became publicly notable in July 2020 after initially appearing to be a rare example of macOS ransomware. The article notes it was later assessed as ineffective in the wild and possibly a proof of concept or early-stage project.
SentinelLabs analyzed the EvilQuest malware and created a decryptor for potential victims. The reference does not provide an explicit date for when this analysis and decryptor release occurred.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.