It was observed late June this year that the malware EvilQuest (also known as ThiefQuest), has been evolving pretty fast. It has become more sinister than earlier even after the ransomware (not anymore) has removed its file encryption capabilities.
Author Saif Ahmed Bhuiyan | NITS DiGi, July 28, 2020
Variation of the EvilQuest/ThiefQuest
Just days after the detection of older variants, expert researchers have found some improved EvilQuest/ThiefQuest variants with stronger capabilities.
A new routine for computing and calling the new functions’ addresses has been implemented by the malware authors. These new and different variants have even obfuscated the function names to make malware tracing even more difficult when it was compared with earlier iterations of the malware.
According to experts “The malware has included new anti-analysis functions (some empty and some functioning) for condition checks like getting the MAC address, CPU count, and physical memory of the machine”.
More security tools has also been included by many security solution providers such as
- Avast Bitdefender
- Little Snitch
- Norton and
To the list of check and termination processes.
The history of Evolution
According to the outcome of the authors of malware, it seems like they are continuously improving EvilQuest/ThiefQuest. According to the research, the malware’s evolution looks as follows:
- ThiefQuest was initially a backdoor (June 4, 2020 sample) with the capability to modify the victim’s host file. Later it adopted File exfiltration capabilities (June 26, 2020 sample), and Ransomware behavior, and File infector behavior (July 2, 2020 sample).
- In the latest versions, the malware continued with the File infector capability and removed the Ransomware capability (July 3, 2020 sample).
- In mid-July, ThiefQuest operators used pirated software installers (including Little Snitch, Ableton, and Mixed In Key), and later it used keylogging and backdoor code in its ransomware strain to hide its true intentions.
With high awareness of the EvilQuest/ThiefQuest, it is certain that attackers have increased interest in targeting macOS. EvilQuest/ThiefQuest operators are making it an even more dangerous threat with such attacks.