This macOS malware can wipe your entire device null


MacOS users are being warned to monitor their device security following the discovery of a potentially hugely damaging new form of ransomware.
Known as ThiefQuest, the malware targets macOS devices such as MacBooks, encrypting the entire system and stealing valuable data on the device.
If a ransom is not paid to release the files, then ThiefQuest is programmed to completely wipe the victim’s device, deleting all items within – however there may be a way to stop it for good.
MacOS malware
ThiefQuest was first detected by researchers at security firm SentinelOne, who were able to carry out a full investigation into the malware.
The company first believed the malware was lacking certain finesse when investigating the ransom message alerting ThiefQuest victims to their fate.
As usual with such alerts, it order victims to pay $50 within 72 hours if they wanted their files returned – however, it neglected to provide any contact email for information about decryption once this was paid, only a link to a ReadMe file containing details on a Bitcoin wallet to send the ransom funds to.
SentinelOne’s research found that ThiefQuest (initially known as EvilQuest) used a custom encryption routine, and that its code suggested it was unrelated to the public key encryption methods commonly used for such attacks.
The researchers discovered ThiefQuest was instead looking in the system’s /Users folder to try and steal files, with .doc, .pdf and .jpg items all targeted among others. However once found, these files were encrypted by a function that used a simple encoding tool that, when creating an encrypted file, simply added an extra data block containing the encryption/decryption key and the key that encodes it.
The attackers also failed to remove the function responsible for the decryption job, meaning getting the original file back was incredibly straightforward, and allowing SentinelOne to create and release a decryptor, which can be downloaded for free now.
Via BleepingComputer
MacOS users are being warned to monitor their device security following the discovery of a potentially hugely damaging new form of ransomware. Known as ThiefQuest, the malware targets macOS devices such as MacBooks, encrypting the entire system and stealing valuable data on the device. If a ransom is not paid…
Recent Posts
- Reddit is reportedly experiencing some outages
- Google may be close to launching YouTube Premium Lite
- Someone wants to sell you a digital version of the antiquated typewriter but without a glued-on keyboard (no really)
- Carbon removal is the next big fossil fuel boom, oil company says
- This is probably the best looking docking station I’ve ever seen in my entire life – and I can’t wait to test it
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010