Inside the Operations of Crazy Evil: The Rise of a Global Crypto-Focused Cybercrime Network
ID: ef86c84a-2c86-5bad-a73b-8891ebb966ca
STIX ID: report--ef86c84a-2c86-5bad-a73b-8891ebb966ca
Feed Name: Brandefense Blog
Crazy Evil is profiled as a Russian-speaking, financially motivated traffer network active since 2021 that conducts large-scale Web3-focused social engineering and multi-OS infostealer campaigns to steal cryptocurrency, NFTs, and account credentials. The report describes their initial-access methods (fake NFT airdrops, influencer impersonation, Telegram/Discord/Discord/X phishing, malvertising, job interview scams), persistence mechanisms (registry/autostart, macOS launch agents, malicious browser extensions, cloud token theft), C2 infrastructure (Telegram bots, encrypted dashboards, fast-flux domains), known malware families (RedLine, Lumma, Rhadamanthys, MetaStealer), recent expansion and scaling through 2024, and recommended defenses such as hardware wallets, phishing-resistant MFA (FIDO2), extension audits, and user education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
