ATT&CKSoftwareThiefQuest

ThiefQuest

S0595

Malware.View on attack.mitre.org

About this malware

ThiefQuest is a virus, data stealer, and wiper that presents itself as ransomware targeting macOS systems. ThiefQuest was first seen in 2020 distributed via trojanized pirated versions of popular macOS software on Russian forums sharing torrent links. Even though ThiefQuest presents itself as ransomware, since the dynamically generated encryption key is never sent to the attacker it may be more appropriately thought of as a form of wiper malware.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1036.005
Match Legitimate Resource Name or Location

ThiefQuest prepends a copy of itself to the beginning of an executable file while maintaining the name of the executable.

T1041
Exfiltration Over C2 Channel

ThiefQuest exfiltrates targeted file extensions in the /Users/ folder to the command and control server via unencrypted HTTP. Network packets contain a string with two pieces of information: a file path and the contents of the file in a base64 encoded string.

T1056.001
Keylogging

ThiefQuest uses the CGEventTap functions to perform keylogging.

T1057
Process Discovery

ThiefQuest obtains a list of running processes using the function kill_unwanted.

T1059.002
AppleScript

ThiefQuest uses AppleScript's osascript -e command to launch ThiefQuest's persistence via Launch Agent and Launch Daemon.

T1071.001
Web Protocols

ThiefQuest uploads files via unencrypted HTTP.

T1105
Ingress Tool Transfer

ThiefQuest can download and execute payloads in-memory or from disk.

T1106
Native API

ThiefQuest uses various API to perform behaviors such as executing payloads and performing local enumeration.

T1486
Data Encrypted for Impact

ThiefQuest encrypts a set of file extensions on a host, deletes the original files, and provides a ransom note with no contact information.

T1497.003
Time Based Checks

ThiefQuest invokes time call to check the system's time, executes a sleep command, invokes a second time call, and then compares the time difference between the two time calls and the amount of time the system slept to identify the sandbox.

T1518.001
Security Software Discovery

ThiefQuest uses the kill_unwanted function to get a list of running processes, compares each process with an encrypted list of “unwanted” security related programs, and kills the processes for security related programs.

T1543.001
Launch Agent

ThiefQuest installs a launch item using an embedded encrypted launch agent property list template. The plist file is installed in the ~/Library/LaunchAgents/ folder and configured with the path to the persistent binary located in the ~/Library/ folder.

T1543.004
Launch Daemon

When running with root privileges after a Launch Agent is installed, ThiefQuest installs a plist file to the /Library/LaunchDaemons/ folder with the RunAtLoad key set to true establishing persistence as a Launch Daemon.

T1554
Compromise Host Software Binary

ThiefQuest searches through the /Users/ folder looking for executable files. For each executable, ThiefQuest prepends a copy of itself to the beginning of the file. When the file is executed, the ThiefQuest code is executed first. ThiefQuest creates a hidden file, copies the original target executable to the file, then executes the new hidden file to maintain the appearance of normal behavior.

T1564.001
Hidden Files and Directories

ThiefQuest hides a copy of itself in the user's ~/Library directory by using a . at the beginning of the file name followed by 9 random characters.

View all 18 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References3

  1. Reed thiefquest fake ransom Open source
    Thomas Reed. (2020, July 7). Mac ThiefQuest malware may not be ransomware after all. Retrieved March 18, 2021.
  2. reed thiefquest ransomware analysis Open source
    Thomas Reed. (2020, July 7). Mac ThiefQuest malware may not be ransomware after all. Retrieved March 22, 2021.
  3. wardle evilquest partii Open source
    Patrick Wardle. (2020, July 3). OSX.EvilQuest Uncovered part ii: insidious capabilities. Retrieved March 21, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.