People have always thought that only Windows is an operating system that is vulnerable to attacks, but this is a big misunderstanding. Mac and Linux are not without vulnerabilities, and some problems are even more serious than others. Recently, security researchers have discovered a new ransomware virus on the macOS platform. Its existence is enough to keep users and developers alert. There is no absolutely safe operating system in the world.
Security personnel discover macOS malware “ThiefQuest”, a two-in-one ransomware and spyware
ThiefQuest, once known as EvilQuest in the past, may seem benign, but is actually more sinister than a destructive intrusion. Like many malware, it is infected through careless or unintentional downloading by users. The bad news is that if you do get infected, you won’t actually be able to rescue any encrypted files. Ironic as it may sound, this part of ThiefQuest’s ransomware may be a newly added mechanism, or it may actually be designed to give users a false hope.

According to security researchers at K7 Labs Content posted by Dinesh DevadossIn addition to ransomware, ThiefQuest also has a full set of spyware capabilities that allow it to steal data from infected computers, search the system for passwords and cryptocurrency wallet data, and run a powerful keylogger to obtain passwords, card numbers or other information, Zhong said. The spyware component also serves as a backdoor lurking on the infected device and serves as a portal for long-term exfiltration, meaning it will remain there even after your computer is rebooted and can be used as an entry and exit point for other viruses or second-stage attacks.
#macOS #ransomware impersonating as Google Software Update program with zero detection.
MD5:
522962021E383C44AFBD0BC788CF6DA3 6D1A07F57DA74F474B050228C6422790 98638D7CD7FE750B6EAB5B46FF102ABD@philofishal @patrickwardle @thomasareed pic.twitter.com/r5tkmfzmFT— Dinesh_Devadoss (@dineshdina04) June 29, 2020
Security personnel pointed out that from the source code, ransomware and spyware can be used as two independent malware if the backdoor logic is separated, but writing them together seems to be someone designing a Mac malware that allows unscrupulous people to completely remotely control the infected device, and the additional ransomware will make money for them. Although ThiefQuest has powerful features, it is unlikely that users will become infected unless they download unverified pirated software. Thomas Reed, director of Mac and mobile platforms at security firm Malwarebytes, discovered that ThiefQuest was spreading from websites bundled with branded software such as security software Little Snitch, DJ Mixed In Key and music production platform Ableton. K7’s Devadoss noted that the malware itself is designed to look like “Google Software Updater.” So far, though, researchers say there don’t appear to be many downloads, and no ransom has been paid to the Bitcoin address provided by the attackers.

The threat of ransomware is everywhere, but since the first complete Mac ransomware appeared four years ago, there have not been many viruses specifically designed to target Apple’s Mac computers. Many users even think that macOS has an indestructible body and cannot be infected with viruses. However, in fact, this is a huge blow to their self-confidence. For the security of your personal information, be careful before obtaining any software downloaded from the Internet.
◎Data source:SlashGear、Ars Technica
Source: KOCPC Chinese
