logo

Inside the Operations of Crazy Evil: The Rise of a Global Crypto-Focused Cybercrime Network

ID: ef86c84a-2c86-5bad-a73b-8891ebb966ca

STIX ID: report--ef86c84a-2c86-5bad-a73b-8891ebb966ca

Feed Name: Brandefense Blog

Threat Score
75/100

Date Published: 2026-03-22

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

Crazy Evil is profiled as a Russian-speaking, financially motivated traffer network active since 2021 that conducts large-scale Web3-focused social engineering and multi-OS infostealer campaigns to steal cryptocurrency, NFTs, and account credentials. The report describes their initial-access methods (fake NFT airdrops, influencer impersonation, Telegram/Discord/Discord/X phishing, malvertising, job interview scams), persistence mechanisms (registry/autostart, macOS launch agents, malicious browser extensions, cloud token theft), C2 infrastructure (Telegram bots, encrypted dashboards, fast-flux domains), known malware families (RedLine, Lumma, Rhadamanthys, MetaStealer), recent expansion and scaling through 2024, and recommended defenses such as hardware wallets, phishing-resistant MFA (FIDO2), extension audits, and user education.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.