[an error occurred while processing the directive]
RSS
Логотип
Баннер в шапке 1
Баннер в шапке 2
2020/07/02 16:28:33

EvilQuest the Malware racketeer for MacOS

.

2020

BleepingComputer announce in June the new type of malwares which received the name EvilQuest, intended for attacks on machines under control of MacOS.

EvilQuest is detected in K7 Lab company and analyzed by group of researchers of Malwarebytes, Jamf and BleepingComputer. It ciphers files in the compromised system, but, masking under the normal racketeer, has also potential on collection of information from the infected host, including the keylogger and theft of these cryptocurrency wallets.

Apparently, the malware appeared at the beginning of June, 2020. It extends through torrents by means of the infected installers of the legal software, in particular the musical Mixed In Key and Ableton programs.

EvilQuest will be checked whether it is started on the virtual machine and also existence in the attacked system of popular anti-virus products (Avast, Kaspersky, McAfee, etc.). After enciphering of files it suggests to pay $50 for static bitcoin a purse, however does not leave any method of a feedback that makes impossible a payment binding to the specific victim.

Actually, after payment by the victim of the redemption the hacker all the same will remain in a system and will collect data interesting him, and files and will remain ciphered.

Researchers believe that the ransomware functions are only masking for theft of data from the infected machine. EvilQuest steals text files, images, spreadsheets, certificates, data of cryptopurses and so forth. At the same time files should not exceed size 800 KB.

Rasshifrovshchik is absent yet and it is not clear whether there will be he in general.

In article the reference to the free Wardle RansomWhere utility which helps to prevent attempts of EvilQuest on enciphering of files is given. Also, we believe, in the shortest time the malware will come to light all popular anti-virus software (MalwareBytes assure that already).

EvilQuest is the third revealed strain of racketeers for MacOS after KeRanger and Patcher.

See Also