Trojan is being detected by Sophos as Miner-D, but is also known as DevilRobber. Trojan is hiding inside pirated versions of the Mac OS X image editing application GraphicConverter version 7.4. Trojan creates a backdoor for remote access and installs a Bitcoin miner that uses up spare CPU or GPU cycles. Trojan also hunts for files that match pthc , an expression used on the Internet sometimes to denote preteen hardcore pornography.
Source: https://threatpost.com/mac-os-x-trojan-goes-bitcoin-mining-steals-files-103011/75820/

