{
  "id": 8900529,
  "title": "Downloading Zoom or Brave? Could Be New Mac Malware ‘Sonoma’ In Disguise",
  "url": "https://urgent.news/2026/09/21/downloading-zoom-or-brave-could-be-new-mac-malware-sonoma-in-disguise",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-21T04:11:58.000Z",
  "source": {
    "name": "HackerNoon",
    "slug": "hackernoon",
    "url": "https://hackernoon.com/downloading-zoom-or-brave-could-be-new-mac-malware-sonoma-in-disguise?source=rss"
  },
  "original_language": "en",
  "account": "The Crazy Evil cybercrime group has been active since August 2024, targeting cryptocurrency, Web3, and collaboration-software users with high-conversion social engineering attacks. Their latest malware family, Sonoma, is a macOS-infostealer built using a Swift backend and loader. The group, identified by the persona ev1lc0rp, has replaced older AMOS (Atomic macOS Stealer) tooling with the newer Sonoma family. Sonoma's infection chain involves a lure in the form of a DMG or ZIP file masquerading as popular collaboration or web3 apps, a launcher that strips quarantine attributes and decrypts embedded config, a secondary payload staging phase, and a core Swift-based stealer that extracts passwords, browser data, developer secrets, and cryptocurrency wallets. The malware uses Apple's built-in tools to avoid detection by antivirus and EDR sensors. Victims are lured through legitimate-looking downloads, which upon first run strip Gatekeeper's quarantine flag and proceed to inject a second stage. The malware asks for the user's Mac login password, mimicking a legitimate system dialog to ensure a working password is provided. The group continues to use this multi-stage infection method across various collaboration and web3 brands, including StreamYard, Zoom, Slack, DocSend, Brave Talk, Riverside, and others.",
  "summary": "New macOS stealer Sonoma hides in fake StreamYard, Zoom, Slack, and DocSend installers, then steals passwords, browser data, and crypto wallets.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}