OSX.EvilQuest Uncovered, analyzing a new piece of mac ransomware
released on 2020-06-30 @ 05:55:17 PM
Early today, the noted Malware researcher Dinesh Devadoss tweeted about a new piece of macOS ransomware "impersonating as Google Software Update program with zero detection."
From Dinesh’s tweet, it was not apparent how the ransomware was able to infect macOS users. However, Thomas Reed of Malwarebytes (and Objective by the Sea speaker!), noted that the malware had been found in pirated versions of popular macOS software, shared on popular torrent sites.
This method of infection, though relatively unsophisticated is somewhat common, thus indicating it is (at least at some level) successful.