Crazy Evil is a Russian-speaking cybercriminal group focused on cryptocurrency theft and related fraud. Active since at least 2021, it is known for social-engineering-heavy operations that target digital-asset users, including cryptocurrency holders and influencers, through tailored phishing and social-media lures. The group has been described as a prolific cryptoscam operation that combines identity fraud, credential-harvesting-style deception, and malware-enabled theft to compromise victims and steal digital assets. The group operates through a coordinated network of social-engineering operators, often described as traffers, who redirect legitimate users to malicious phishing infrastructure and scam pages. Reported subteams include AVLAND, TYPED, DELAND, ZOOMLAND, DEFI, and KEVLAND, each associated with bespoke scam themes and victim targeting. Campaigns attributed to Crazy Evil have included multiple concurrent social-media scams and fake crypto-related brands used to lure victims into installing malware or surrendering access to wallets and accounts. Crazy Evil commonly deploys information-stealing malware and crypto-focused theft tooling, including StealC, Atomic macOS Stealer (AMOS), and Rhadamanthys, with activity spanning both Windows and macOS environments. Its tradecraft centers on initial access via phishing and spoofed online personas, followed by credential theft, exfiltration of sensitive data, and direct cryptocurrency theft. The actor’s operations are strongly associated with social engineering, spoofing, and malware delivery rather than disruptive or destructive objectives. Infrastructure and certificate-overlap reporting has also linked Crazy Evil activity to broader cybercrime ecosystems and other traffer groups, including Marko Polo and Wagmi, suggesting participation in a wider criminal service economy. The group’s dominant motivation is financial gain through theft of digital assets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A separate threat actor mentioned because it shares overlapping code-signing certificate sources with GoldenEyeDog subgroups. It specializes in social engineering and cryptocurrency theft and regularly uses code-signing certificates to avoid SmartScreen warnings.
Russian-speaking cybercrime group running social-media-driven scams for identity fraud and cryptocurrency theft, delivering multiple stealers and crypto-drainer malware.
Referenced as a trafficker team using more traditional malware-based approaches (contrast point to Rublevka Team’s JavaScript-based draining).
Named as a traffer group potentially linked via shared infrastructure to a broader crypto-theft/social-engineering ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.