Downloading Zoom or Brave? Could Be New Mac Malware ‘Sonoma’ In Disguise

https://hackernoon.imgix.net/images/l7noBCUFwmcERrcGKL5jHUS0UcV2-ia1h3qr6.png

Moonlock Lab first wrote about Crazy Evil in August 2024, when the group was pushing an AMOS-style stealer behind fake Loom downloads. Two years later they are still in the same business – collaboration-app lures, crypto-adjacent victims – but the tooling has been rebuilt.

In 2026, the Crazy Evil traffer team is still active, and their macOS tooling has moved to a newer family, internally marked SONOMAC1 and informally called Sonoma. It is a compiled Swift infostealer with its own loader family designed to harvest passwords, browser data, developer secrets, and cryptocurrency wallets while staying quieter against antivirus and EDR sensors.

This piece walks through who is behind it, how the malware works, why PAM password checks matter, and why a label of “PamStealer / Avenger” does not apply to this family.

Who is Crazy Evil

Crazy Evil is a traffer-style cybercrime operation that specializes in high-conversion social engineering against...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more