New Mac Ransomware Found in Pirated Mac Apps - MacRumors
Skip to Content

New Mac Ransomware Found in Pirated Mac Apps

There's a new 'EvilQuest' Mac ransomware variant that's spreading through pirated Mac apps, according to a new report shared today by Malwarebytes. The new ransomware was found in pirated download for the Little Snitch app found on a Russian forum.

evilquestransomalert
Right from the point of download, it was clear that something was wrong with the illicit version of Little Snitch, as it had a generic installer package. It installed the actual version of Little Snitch, but it also installed an executable file named "Patch" into the /Users/Shared directory and a post-install script for infecting a machine.

The installation script moves the Patch file into a new location and renames it CrashReporter, a legitimate macOS process, keeping it hidden in Activity Monitor. From there, the Patch file installs itself in several spots on the Mac.

The ransomware encrypts settings and data files on the Mac, like Keychain files, resulting in an error when attempting to access the iCloud Keychain. The Finder also malfunctioned after installation, and there were problems with the dock and other apps.

Malwarebytes found the ransomware to work poorly and was not able to get instructions on paying the ransom, but a screenshot found on the forums where the malicious software originated suggests it's meant to prompt users to pay $50 to recover access to their files. Note: anyone infected with this ransomware or any ransomware should not pay the fee, because it does not remove the malware.

Along with the ransom activity, the malware may also install a keylogger for monitoring keystrokes, but what the malware does with the functionality is unknown. Malwarebytes says that its software for Mac is able to remove the ransomware, detected as Ransom.OSX.EvilQuest. Encrypted files will require a restore from a backup, though.

Similar ransomware was found in other pirated apps, and Mac users can avoid it by staying away from pirated apps and untrustworthy websites and forums that offer illicit downloads.

Popular Stories

imac video apple feature

Apple Released Two New Accessories This Month

Friday May 22, 2026 12:24 pm PDT by
May has been a quiet stretch in terms of new Apple products, but the company did release two accessories on its online store this month. First up was a new Pride Edition Sport Loop for the Apple Watch. The band features a rainbow design with 11 colors of woven nylon yarns. U.S. pricing is set at $49. The band is part of Apple's 2026 Pride Collection, which also includes a new Pride...
Apple Event Logo

Apple to Release These 15 New Products Later This Year

Friday May 22, 2026 6:36 am PDT by
April and May have been relatively slow months for Apple this year, but there is a lot to look forward to heading into WWDC 2026 and beyond. Apple is expected to release at least 15 more products later this year, with some of them held up until the more personalized version of Siri launches. Beyond the usual annual updates to iPhones and Apple Watches in September, Apple's all-new smart...
Aston Martin CarPlay Ultra Screen

Apple Says CarPlay Ultra is Coming to These Vehicle Brands

Thursday May 21, 2026 11:53 am PDT by
Last year, Apple launched CarPlay Ultra, the long-awaited next-generation version of its CarPlay software system for vehicles. Nearly a year later, CarPlay Ultra is still limited to Aston Martin's latest luxury vehicles, but that should change fairly soon. In May 2025, Apple said many other vehicle brands planned to offer CarPlay Ultra, including Hyundai, Kia, and Genesis. CarPlay Ultra...

Top Rated Comments

Apple Macintosh 128K Avatar
77 months ago
Stick to legit apps from legit services and you'll be fine. Also keep an eye to make sure the apps are properly signed.

To have this happen you have to bypass macOS security and allow the non-signed installer run. It's like giving the keys to your house to some questionable person on the street and then being surprised when they take your stuff.
Score: 30 Votes (Like | Disagree)
77 months ago
While more ransomware on Macs is not welcome pirates get what pirates get.
Score: 25 Votes (Like | Disagree)
Mr_Brightside_@ Avatar
77 months ago

Not to worry, this is what developers want apparently, rather than paying 30% to Apple.
I'm not sure you understand the situation fully...
Score: 17 Votes (Like | Disagree)
swm Avatar
77 months ago
in any case, if this happens to you, a 2 step procedure will save the day:
- boot into internet recovery (can't be sure if the on-disk recovery data is compromised)
- reinstall from timecapsule
Score: 17 Votes (Like | Disagree)
77 months ago
That's what you get for pirating apps.
Score: 16 Votes (Like | Disagree)
77 months ago
No sympathy for anyone that pirates software.
Score: 13 Votes (Like | Disagree)