ThiefQuest
Associated Software Descriptions |
|
Name | Description |
---|---|
EvilQuest | (Citation: Reed thiefquest fake ransom) |
MacRansom.K | (Citation: SentinelOne EvilQuest Ransomware Spyware 2020) |
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols |
ThiefQuest uploads files via unencrypted HTTP. (Citation: wardle evilquest partii)(Citation: reed thiefquest ransomware analysis) |
Enterprise | T1059 | .002 | Command and Scripting Interpreter: AppleScript |
ThiefQuest uses AppleScript's |
Enterprise | T1543 | .001 | Create or Modify System Process: Launch Agent |
ThiefQuest installs a launch item using an embedded encrypted launch agent property list template. The plist file is installed in the |
.004 | Create or Modify System Process: Launch Daemon |
When running with root privileges after a Launch Agent is installed, ThiefQuest installs a plist file to the |
||
Enterprise | T1564 | .001 | Hide Artifacts: Hidden Files and Directories |
ThiefQuest hides a copy of itself in the user's |
Enterprise | T1562 | .001 | Impair Defenses: Disable or Modify Tools |
ThiefQuest uses the function |
Enterprise | T1056 | .001 | Input Capture: Keylogging |
ThiefQuest uses the |
Enterprise | T1036 | .005 | Masquerading: Match Legitimate Name or Location |
ThiefQuest prepends a copy of itself to the beginning of an executable file while maintaining the name of the executable.(Citation: wardle evilquest partii)(Citation: reed thiefquest ransomware analysis) |
Enterprise | T1518 | .001 | Software Discovery: Security Software Discovery |
ThiefQuest uses the |
Enterprise | T1497 | .003 | Virtualization/Sandbox Evasion: Time Based Evasion |
ThiefQuest invokes |
References
- Patrick Wardle. (2020, July 3). OSX.EvilQuest Uncovered part ii: insidious capabilities. Retrieved March 21, 2021.
- Phil Stokes. (2020, July 8). “EvilQuest” Rolls Ransomware, Spyware & Data Theft Into One. Retrieved April 1, 2021.
- Thomas Reed. (2020, July 7). Mac ThiefQuest malware may not be ransomware after all. Retrieved March 18, 2021.
- Thomas Reed. (2020, July 7). Mac ThiefQuest malware may not be ransomware after all. Retrieved March 22, 2021.
- Patrick Wardle. (2020, June 29). OSX.EvilQuest Uncovered part i: infection, persistence, and more!. Retrieved March 18, 2021.
- Gabrielle Joyce Mabutas, Luis Magisa, Steven Du. (2020, July 17). Updates on Quickly-Evolving ThiefQuest macOS Malware. Retrieved April 26, 2021.
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.