Urgent.News

What's breaking now, across thousands of outlets.

Tech

Downloading Zoom or Brave? Could Be New Mac Malware ‘Sonoma’ In Disguise

New macOS stealer Sonoma hides in fake StreamYard, Zoom, Slack, and DocSend installers, then steals passwords, browser data, and crypto wallets.

Downloading Zoom or Brave? Could Be New Mac Malware ‘Sonoma’ In Disguise

The Crazy Evil cybercrime group has been active since August 2024, targeting cryptocurrency, Web3, and collaboration-software users with high-conversion social engineering attacks. Their latest malware family, Sonoma, is a macOS-infostealer built using a Swift backend and loader. The group, identified by the persona ev1lc0rp, has replaced older AMOS (Atomic macOS Stealer) tooling with the newer Sonoma family.

Sonoma's infection chain involves a lure in the form of a DMG or ZIP file masquerading as popular collaboration or web3 apps, a launcher that strips quarantine attributes and decrypts embedded config, a secondary payload staging phase, and a core Swift-based stealer that extracts passwords, browser data, developer secrets, and cryptocurrency wallets.

The malware uses Apple's built-in tools to avoid detection by antivirus and EDR sensors. Victims are lured through legitimate-looking downloads, which upon first run strip Gatekeeper's quarantine flag and proceed to inject a second stage. The malware asks for the user's Mac login password, mimicking a legitimate system dialog to ensure a working password is provided.

The group continues to use this multi-stage infection method across various collaboration and web3 brands, including StreamYard, Zoom, Slack, DocSend, Brave Talk, Riverside, and others.

Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at hackernoon.com →

More in Tech

More from Monday 21 September →