Crazy Evil is a Russian-speaking cybercriminal group active since at least 2021 that specializes in cryptocurrency-focused fraud, credential theft, and malware-enabled theft of digital assets. The group is known for running large-scale social engineering operations that target cryptocurrency users, traders, and influencers, and has been described as one of the more prolific criminal actors operating in the digital-asset scam ecosystem. A defining feature of Crazy Evil’s operations is its use of traffers: social engineering operators who redirect legitimate users to phishing and scam infrastructure through tailored lures, often delivered via social media and other online engagement channels. The group combines identity fraud, bespoke phishing, and fake project or investment themes to induce victims to install malware or surrender access to wallets and accounts. Its campaigns are tailored to specific victim profiles rather than relying solely on generic mass phishing. Crazy Evil has been linked to multiple concurrent scam operations and to the use of information-stealing and credential-theft malware including StealC, Atomic macOS Stealer (AMOS), and Rhadamanthys. Its tradecraft supports cross-platform victimization, including both Windows and macOS users, reflecting a focus on cryptocurrency communities where mixed-device environments are common. The group’s activity spans both direct wallet theft and broader compromise of credentials and personal information that can facilitate follow-on fraud. Reporting has associated Crazy Evil with several internal subteams or subdivisions, including AVLAND, TYPED, DELAND, ZOOMLAND, DEFI, and KEVLAND. These subgroups appear to support specialized scam themes and victim targeting models within the broader organization. Crazy Evil has also been discussed alongside other traffer or crypto-scam ecosystems, including Marko Polo and Wagmi, in the context of shared or overlapping infrastructure. Known aliases include crazyevil and crazy_evil. Overall, Crazy Evil is best characterized as an organized, Russian-speaking financially motivated threat actor focused on industrialized social engineering, phishing, and infostealer deployment to steal cryptocurrency and related digital assets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian-speaking cybercrime group running social-media-driven scams for identity fraud and cryptocurrency theft, delivering multiple stealers and crypto-drainer malware.
Referenced as a trafficker team using more traditional malware-based approaches (contrast point to Rublevka Team’s JavaScript-based draining).
Named as a traffer group potentially linked via shared infrastructure to a broader crypto-theft/social-engineering ecosystem.
Conducting cryptocurrency-focused cybercrime involving identity fraud, cryptocurrency theft, information-stealing malware, phishing pages, and social engineering via traffers. The group runs bespoke scams targeting specific victim profiles, including cryptocurrency users and influencers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.