Mac users - Beware - EvilQuest ransomware impersonates Google & Apple OS Processes

imhotep

Well-known member
  • Mar 29, 2017
    14,825
    8
    35,338
    113
    EvilQuest ransomware appears to be spreading through pirated macOS apps, disguising its background processes as Apple’s CrashReporter or Google Software Update.
    On the bright side it requests only $50 for the files to be decrypted. But it's infecting only through pirated Mac applications.
     
    • Like
    Reactions: Night Rider

    Night Rider

    Well-known member
  • Feb 18, 2016
    2,992
    6,174
    113
    Can use the SentinelOne's recently released decryption tool designed to restore data encrypted by EvilQuest.
     
    • Like
    Reactions: imhotep