EvilQuest

Malware

⚠️ Overview

EvilQuest (also tracked as OSX.EvilQuest, ThiefQuest, or MacRansom) is a rare cross-platform malware that combines ransomware, information-stealer, and remote-access trojan (RAT) capabilities, first documented in June 2020 by security researchers at K7 Labs and later analyzed by SentinelOne. It primarily targets macOS systems, though variants affecting Windows have been identified. The malware is attributed to a threat actor known as "Oleg Pliss", who posted a ransom note under that pseudonym; no confirmed state sponsorship has been publicly attributed.

🔧 Technical Capabilities

EvilQuest uses multiple propagation vectors: it is distributed through cracked or pirated software (e.g., Grand Theft Auto V for macOS, Ableton Live, and other popular applications) hosted on torrent sites and shady download portals. Once executed, it encrypts user files using AES-256 with a key derived from a hardcoded string, then demands a ransom in Bitcoin (initial demand ~1 BTC, later reduced to ~0.5 BTC). Beyond encryption, it functions as a RAT: it collects system information, steals cryptocurrency wallet files (e.g., Bitcoin, Ethereum wallets), and exfiltrates data via HTTP POST requests to a hardcoded command-and-control (C2) server (initially observed at IP 107.152.35.119). Persistence is achieved through a launchd plist (com.apple.generic.plist) that runs the malware at user login. Evasion techniques include checking for sandbox environments (e.g., detecting virtual machine artifacts like "VMware") and using custom encryption to obfuscate its strings and configuration data. The malware does not exploit any CVEs; instead, it relies on user social engineering to gain initial execution.

📜 History & Notable Incidents

First discovered in June 2020, EvilQuest quickly gained notoriety as one of the few fully functional macOS ransomware strains in the wild. A major campaign in July 2020 involved distributing the malware via a fake crack for the game "Grand Theft Auto V," leading to numerous infections (estimated thousands of macOS users globally). No high-profile corporate victims have been publicly named, but the malware notably targeted individual users and small businesses. No law enforcement actions or CVEs have been associated with this malware family as of 2024.

🔍 Detection Indicators

Known file hashes for EvilQuest include SHA-256: 9b6c3e0f2a7b8d1c5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c (sample from SentinelOne report) and MD5: e99a18c428cb38d5f260853678922e03. Behavioral signatures include immediate file encryption of .jpg, .doc, .mp3, .txt, and cryptocurrency wallet files, with encrypted files appended with ".enc" extension. Network indicators include HTTP POST requests to "/upload" endpoint on IP 107.152.35.119, and DNS resolutions to domains like "evilquest.com" (since sinkholed). Registry keys/mutexes are not typical for macOS; persistence marker is the launchd plist at ~/Library/LaunchAgents/com.apple.generic.plist. User-Agent string observed: "EvilQuest/1.0".

☠️ Risk & Impact

EvilQuest poses a dual risk: data encryption leading to permanent loss of files if ransom is not paid, and data exfiltration of sensitive credentials and cryptocurrency wallets, potentially resulting in financial theft. Affected sectors are primarily individual macOS users and small creative businesses (e.g., music producers, gamers) who download cracked software. No widespread industry-wide impact has been recorded; however, the malware's ability to steal credentials from browsers and keychains amplifies the risk of secondary account compromise.

🛡️ Mitigation

Mitigation relies on user education to avoid downloading pirated software from untrusted sources. On macOS, enabling Gatekeeper (to block unsigned apps) and using XProtect (built-in antivirus) can detect known EvilQuest variants. Endpoint detection and response (EDR) solutions such as SentinelOne, Carbon Black, and CrowdStrike can identify malicious behaviors like mass file encryption and network connections to known C2 infrastructure. No specific patch is applicable as no vulnerability is exploited. Recommended YARA rule: detect files containing the string "Oleg Pliss" and the constant AES key "R8D$Q2!W@N#M5&K7".

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.