Moonlock Lab first
In 2026, the Crazy Evil traffer team is still active, and their macOS tooling has moved to a newer family, internally marked SONOMAC1 and informally called Sonoma. It is a compiled Swift infostealer with its own loader family designed to harvest passwords, browser data, developer secrets, and cryptocurrency wallets while staying quieter against antivirus and EDR sensors.
This piece walks through who is behind it, how the malware works, why PAM password checks matter, and why a label of “PamStealer / Avenger” does not apply to this family.
Crazy Evil is a traffer-style cybercrime operation that specializes in high-conversion social engineering against cryptocurrency, Web3, and collaboration-software users. Public reporting
In August 2024, Moonlock Lab
Sonoma is the next chapter of that story – not a recycled AMOS build pasted into a new DMG, but a custom builder-and-payload pipeline.
The persona behind much of the macOS tooling appears as ev1lc0rp. Build artifacts recovered from the One Crystal Flip launcher even leaked internal paths such as /var/www/evilcorp/backend/templates/macos/launcher.c, which is consistent with a centralized Malware-as-a-Service-style panel that stamps campaign names, icons, and C2 tokens into fresh Mach-O droppers.

At a high level, Sonoma is a multi-stage macOS infection chain:
Generation 2 launchers embed the markers SONOMAC1 and sonomab in the Mach-O __const section, spliced into strings that look like /usr/bin/zsh and com.apple.quarantine. That operator tag is where the name “Sonoma Stealer” comes from – not Apple’s macOS Sonoma release.

Crazy Evil continues to favor conversion over exotic exploits. Someone searching for StreamYard or Slack, or accepting a “join our podcast” calendar invite, downloads a .dmg or .zip. The volume looks like an installer. The binary inside is ad-hoc signed – no Developer ID, no notarization, no Team ID.
On first run the launcher strips Gatekeeper’s quarantine flag (xattr -dr com.apple.quarantine, and in Gen 2 also xattr -cr), then runs a second stage. Older builds dropped /tmp/.appbootstrap.XXXXXX, executed it with /bin/zsh, and unlink()’d it. Newer builds prefer /bin/zsh -s and a pipe, so less lands on disk.
Pic. Strings from a Generation 1 launcher
|
PID |
Command |
What it proves |
|---|---|---|
|
905 |
./launcher |
First stage |
|
1027 |
xattr -dr com.apple.quarantine /Users/admin/Desktop/launcher |
Gatekeeper strip on the stub |
|
968 / 907 |
xattr -cr /Users and xattr -dr … /Users |
Gen 2 also uses -cr; overly broad target in this run |
|
1028, 1032, 1092, 1097 |
zsh -s |
Second stage on a pipe, not .appbootstrap |
|
1035 |
curl …/pkgunpack -o /tmp/.pkgunpack-1028 |
Helper download |
|
1088–1089 |
xattr -cr + codesign -fs - --deep /tmp/.pkgunpack-1028 |
Helper made executable and ad-hoc signed |
|
1091 |
pkgunpack genkey /tmp/.eph-1028.key /tmp/.eph-1028.pub |
Ephemeral key |
|
1090 |
curl …/CoreUpdate.pkg.enc -o /tmp/.core-1028.enc |
Locked blob |
|
1096 |
POST …/v1/loader/dek + eph_pub_b64 |
KEM check-in |
|
1100 |
pkgunpack decrypt … /tmp/.core-1028.tar.gz |
Unwrap |
|
1102 |
tar xzf … -C /tmp/.upd-1028 |
Unpack installer |
|
1105–1107 |
xattr -cr + codesign + open -gn …/StreamYardInstaller.app |
Fake app launched hidden |
|
1108 |
…/StreamYardInstaller.app/Contents/MacOS/dm5ne99sw9 |
Swift core |
|
1033 |
rm -rf /tmp/.upd-1028 /tmp/.core-1028.enc … |
Wipe staging |
Table 1. Sandbox process tree for the StreamYard Gen-2 launcher. Quarantine strip (xattr -dr / xattr -cr), piped zsh -s, then the pkgunpack KEM path into dm5ne99sw9.
A later window asks for the Mac login password, dressed as a system dialog. If the password is wrong, the dialog shakes and asks again. That loop is the point: the operators want a working password, not a typo.
Legitimate StreamYard and similar products run in the browser. They do not ship an unsigned “installer.app” that immediately asks for your login password.

The fake installer is not only StreamYard. The same chain has shipped as meeting, document, wallet-adjacent, and regional-browser brands. Brands we have seen so far:

Moonlock telemetry already shows Sonoma activity on customer Macs. In the snapshot below, detections concentrate in Spain and Japan – useful as a reminder that this is live traffic, not a lab-only sample set.
Note: Moonlock telemetry for this snapshot comes only from Macs running Moonlock or CleanMyMac, so the map is a view into our install base, not a full picture of worldwide infections. Blank countries do not mean Sonoma is absent there. We still read this as an active, growing campaign, and we will post follow-up telemetry and findings on
Pic. Moonlock telemetry snapshot: Sonoma Stealer activity
The sample we analyzed is a universal FAT Mach-O compiled as Swift with Cocoa/AppKit UI and links to libpam.2.dylib, libsqlite3.dylib, and Security.framework. It runs as a background-style app (LSUIElement set so it stays off the Dock).
Older commodity macOS stealers, including much of the AMOS ecosystem, often validate a phished password by shelling out to tools like dscl, or by driving an AppleScript display dialog. Those patterns are noisy for EDR: they create child processes and distinctive command lines.
Sonoma’s core takes a quieter path:
That PAM shift is a deliberate anti-detection improvement: fewer suspicious shell children, same practical outcome for the attacker.
Pic. Load commands / imported dylibs in the core: AppKit, Security.framework, /usr/lib/libpam.2.dylib, /usr/lib/libsqlite3.dylib
Pic. Imported PAM symbols.
Pic. AppKit prompt class MacClient.SystemInputShell and the auth.* localization keys
Browser cookie and login databases are SQLite files that are often locked while Chrome, Brave, Arc, Edge, Opera, Firefox, Safari, and similar apps are running. Blind cp fails with SQLITE_BUSY.
Sonoma links libsqlite3.dylib and uses SQLite’s online backup APIs (sqlite3_backup_init / sqlite3_backup_step) to clone Cookies, Login Data, Web Data, and related stores into memory-friendly replicas. Combined with broad Chromium and Gecko coverage, that is a meaningful reliability upgrade over “copy the file and hope.”
Pic. SQLite online backup
Across samples and staging notes, the stealer’s shopping list is familiar but thorough:
Harvested data is packaged and uploaded over HTTPS to attacker’s servers such as 109[.]94.171.225:443 (Greencloud LLC), often with retry/backoff and cleanup of /tmp staging files after success.
One of Sonoma’s more interesting evasion tricks is abusing Apple iCloud Calendar (CalDAV) as a payload host.
In the Toria.dmg chain, after quarantine stripping, the launcher curls a Loader.app.tar.gz from gateway.icloud.com/caldav/..., extracts it under /tmp/.ldr-*, strips attributes, ad-hoc signs the app, and launches it. Later stages add anti-debug (ptrace(PT_DENY_ATTACH)), AES decryption, and piping into /bin/zsh -s.
Enterprise filters routinely trust *.icloud.com, and the TLS certificate is Apple’s – blocking it breaks real calendar sync. Disposable iCloud accounts thus become a resilient staging CDN.
Pic: Toria chain fetches Loader.app.tar.gz from Apple CalDAV
StreamYard-style launchers also use a pkgunpack helper for a Curve25519 ephemeral exchange against /v1/loader/dek, then AES-GCM-unwrap the core archive, so encrypted blobs captured offline without the live handshake are much harder to decrypt.
Pic. StreamYard path: ad-hoc sign pkgunpack
A practical hunt: legitimate Calendar sync does not look like /usr/bin/curl downloading a .tar.gz from gateway.icloud.com/caldav/ into tar. Chains that pair xattr -cr on /tmp with immediate codesign -fs - --deep also deserve review.
On 14 September 2026, researcher

That label is understandable at a glance (both families validate passwords through PAM), but let’s take a closer look at them.
Jamf Threat Labs
Sonoma is a different codebase. PAM on macOS is not a family name. It is an API. Two stealers can call it without being related.
|
PamStealer (Jamf) |
Sonoma / ev1lc0rp | |
|---|---|---|
|
Language |
Rust Mach-O |
Compiled Swift + AppKit / C-interop |
|
First stage |
.scpt + JXA (NSURLSession) |
Universal Mach-O launcher + zsh pipe |
|
Password UI |
Native NSAlert (Maccy wants to make changes) |
In-process AppKit window (MacClient.SystemInputShell) |
|
Password check |
PAM via Rust FFI |
_pam_authenticate / _pam_verify_login against libpam.2.dylib |
|
Infrastructure |
avenger-sync[.]live, fake Maccy site |
*.appstore[.]com.mx, apple03cloudstore[.]com, 109[.]94.171.225 |
Before SONOMAC1, Crazy Evil’s macOS developer persona was already visible in an earlier loader generation marked EVLCFG01, with the rolling XOR key ev1lc0rp. In the material we compared, that first loader family and the Sonoma (SONOMAC1) builds sit only about a month apart. It’s a short window for a fairly large engineering jump.
Generation 1 showed up as DocSend-style installers (for example DocSendInstaller.zip / MNOBS.zip). The Mach-O launcher carried an EVLCFG01 overlay, decrypted trailer config with the ev1lc0rp key, dropped shell stagers under /tmp/.appbootstrap.*, and leaned on companion scripts such as installer.sh with OpenSSL AES-CBC for payload unwrap. The core name observed in that generation was aa9hb9425l.
Pic. Meendo / MNOBS launcher
Staging still wrote a harvest archive to disk as /tmp/osalogging.zip before uploading it to the attackers server. That zip path is worth a separate note. /tmp/osalogging.zip has long been a practical hunting indicator for MacSync (sometimes discussed as Mac.c) – another commercial macOS stealer family. Seeing the same artifact in Crazy Evil’s EVLCFG01 staging does not prove they forked MacSync wholesale, but it does fit a familiar pattern: traffer teams assembling a new product by borrowing working pieces from more than one existing solution. AMOS-era habits, MacSync-style packaging names, and later a custom Swift core with PAM and CalDAV LotC all show up in the same Crazy Evil timeline.
Pic. StreamYard-hosted stager (streamyard.appstore[.]com.mx). daemon_function waits on /tmp/osalogging.zip
|
Dimension |
Generation 1 (EVLCFG01) |
Generation 2 (SONOMAC1) |
|---|---|---|
|
Magic overlay |
EVLCFG01 |
SONOMAC1 |
|
XOR key |
ev1lc0rp |
sonomab |
|
Single-instance check |
Process listing (ps -c -o comm=) |
Lock directory (/tmp/.sn-dropper-%u.lockdir) |
|
Gatekeeper strip |
xattr -rd com.apple.quarantine |
xattr -rd plus xattr -cr |
|
Secondary delivery |
Direct curl from C2 / appstore.com.mx |
iCloud CalDAV and/or TDS KEM endpoint |
|
Payload decryption |
OpenSSL CLI (AES-CBC) via installer.sh |
pkgunpack (Curve25519 Donna + AES-GCM) |
|
Core payload name |
aa9hb9425l |
dm5ne99sw9 (plus .sys-* runners) |
|
Anti-analysis |
Sandbox uptime (kern.boottime) |
ptrace(PT_DENY_ATTACH), kern.hv_vmm_present, hw.model |
|
Execution |
Drop /tmp/.appbootstrap.* then unlink |
Fileless-leaning /bin/zsh -s pipe |
|
Exfil staging artifact |
/tmp/osalogging.zip (on disk) |
In-memory archive / TLS upload |
Table. Architectural comparison of Crazy Evil’s Generation 1 (EVLCFG01 / ev1lc0rp) loaders versus Generation 2 (SONOMAC1 / sonomab).
Crazy Evil did not disappear after the 2024 campaign. They kept shipping: better launchers, Swift-native harvesting, PAM instead of noisy dscl checks, KEM staging, and CalDAV LotC delivery.
Sonoma is a reminder that macOS actors often win with trust abuse - fake meetings, familiar brands, and almost-official password prompts — more than with zero-days. Separating Sonoma (Swift, Crazy Evil) from PamStealer (Rust, per Jamf) keeps attribution and hunting aimed at the right infrastructure.
Moonlock Lab will keep tracking this cluster as builds rotate. If you want practical coverage on the Mac itself, Moonlock App is the product side of that work.
This publication is independent and is not authorized, sponsored, or approved by Apple Inc. Mac and macOS are trademarks of Apple Inc.
Hashes and hosts below are drawn from Moonlock Lab’s Sonoma / Crazy Evil Generation-1–2 material (including Toria CalDAV staging and apple03cloudstore[.]com campaigns). Treat them as starting points – operators rotate lure brands, builds, and tokens frequently.
|
Hash |
Role |
|---|---|
|
b222f78c1cc4170383817facfa9180da7096f07d9113fbc42904e2cde6e0ad05 |
Core stealer dm5ne99sw9 (universal FAT) — primary / repeatedly cited build |
|
f2345efe4e13ad2c3e831e5c3fba6d1d11ab9ae41f0ee125fb92cc224c681aca |
Core stealer dm5ne99sw9 under /tmp/.upd-1028/ — alternate observed build (same internal name) |
|
b4be845571320766e1e9ea7d62140aca98f57fc618a4ff1bf243a8eaea3f9f3a |
dm5ne99sw9 ARM64 thin slice |
|
77d83e5822e5d5074a2e508941a7fb042e7f892379379e89ec6bc62f2e62654d |
dm5ne99sw9 x86_64 thin slice |
|
afcaf87c21820f83f409feebd7a1edccaa269869386de163c86e33ace1dbc561 |
Staged Info.plist / bundle descriptor (LSUIElement) |
|
53a1064c79dc35caed4d1ddcde485532789cee2cbf140a11e7e2fc40c85259f8 |
StreamYard Gen-2 launcher (SONOMAC1 / sonomab) |
|
47ac4d7fdd9c3bd85a8eef42b04c2399dd51deb6864f68deb493d388fc40dea5 |
Generation-1 DocSend-style launcher (EVLCFG01 / ev1lc0rp) |
|
6e2eb4e95142c7a11183f8f28b1a3eda51bbc435b300ec5199e43d08a876e14a |
pkgunpack Curve25519 Donna + AES-GCM helper |
|
a39d622b89bc3ddd903e9cefd2848d19a039c7d92178969b86f9ecf7ba36df49 |
Toria.dmg (CalDAV LotC chain) |
|
802cd1c10958e202f64c1047c6111946311a7116c3329fc7958b190eac41f806 |
Toria.app/Contents/MacOS/launcher |
|
adc6b308147b68fc6bb9eb2e77e62c8182e3a4f589277aa10d608a101abbb524 |
Loader.app/Contents/MacOS/loader (CalDAV-staged) |
|
c7586e5e4e52e3678ded75d43cd73225fd4bb2f63a945f19a1f23d010a52e7da |
/tmp/.sys-6df1ff3d0b8c2ce1 in-memory / zsh runner |
|
cacb68741b9d19dc6856a4e8cd93ed47c6c0b9cdc708e4b06ca728fd8731b5c3 |
Loader.app/Contents/Info.plist |
|
6c594fb41b6f8414b67cc2921982624f0827789df81e9cacf896385d8b38d643 |
Slack.dmg (apple03cloudstore campaign) |
|
c7bbbd1c00dbbb56a97bb5409107d85273f540d91df2732cdbbbe16681e0ba06 |
Slack.app/.../launcher (SONOMAC1) |
|
69a1979fcf1b9db74620db24b7e3bd07559ac182643f6b88ed97bbd0d4b68dc8 |
CavePay-2.dmg |
|
2704a7cd5f3f0c225a39640137f9d4e12fee50af153bbb8712194cb2eb97b2c7 |
agent.zsh (CavePay stager) |
|
08712e497216cdd0d34651a82380f5103b509ce0184792cedc631d769f436df3 |
Crystal Flip.dmg |
|
c57afa2abaf8626cabe583136e6205ea170d318d155bd9272d90c0395aee6b57 |
agent.zsh (CrystalFlip stager) |
|
14e9cac380b3f1075a8138ab14826bc71db222947fb6477fb71d124e80d6c09d |
CrystalFlip Mach-O launcher (embeds /var/www/evilcorp/.../launcher.c) |
|
f8dbb74ff25627369691c9485e126e3a641fb081b37d51bcf9d67e3da19b748e |
Brave Talk.dmg |
|
1b9ef24d0c55a54c2bfa3d7470d0d66ffd4155886eb13c8749990845bd088d56 |
agent.zsh (Brave Talk stager) |
|
da3f059fc1aca6df4a4496735d361fd7ddbaf123f82ca4df99e5e44cb44c2ebf |
Brave Talk campaign companion artifact (paired with Brave Talk.dmg in TDS notes) |
|
Indicator |
Role |
|---|---|
|
109[.]94[.]171[.]225 |
Central staging / exfil C2 (Greencloud LLC, AS3214) — often :443 |
|
45[.]92[.]156[.]15 |
Related Greencloud origin / ingestion (NL) observed with newer domains |
|
108[.]165[.]164[.]41 |
TDS Robot backend origin (Kyonix AS210457); SSL subject tdsrobot.ltd |
|
appstore[.]com[.]mx |
Campaign apex (malvertising / lookalike installers) |
|
streamyard[.]appstore[.]com[.]mx |
Stage-1 lure + KEM endpoint (/v1/loader/dek) |
|
zoom[.]appstore[.]com[.]mx |
Stage-1 lure host |
|
docsend[.]appstore[.]com.mx |
Stage-1 lure host |
|
meendo[.]appstore[.]com.mx |
Stage-1 lure host |
|
apple03cloudstore[.]com |
Apex C2 / staging / TDS-fronted infrastructure (Cloudflare) |
|
slack[.]apple03cloudstore[.]com |
Gen-2/3 KEM staging (/pkgunpack, /CoreUpdate.pkg.enc, /v1/loader/dek) |
|
brave[.]apple03cloudstore[.]com |
Video-conference lure stager (/agent.zsh) |
|
cavepay[.]apple03cloudstore[.]com |
Crypto invoicing lure stager (/agent.zsh) |
|
crystalflip[.]apple03cloudstore[.]com |
DeFi / gaming lure stager (/agent.zsh) |
|
gateway.icloud.com/caldav/ (abused path pattern) |
LotC secondary payload hosting (…/attach/…/Loader.app.tar.gz/…) — redact long account/attachment tokens; keep host + /caldav/ + /attach/ + archive name |
URL / HTTP path patterns (hunting): /v1/loader/dek (KEM DEK exchange; header X-Upload-Token), /pkgunpack, /CoreUpdate.pkg.enc, /agent.zsh, exfil-style /v1/upload or /exfil on Greencloud receivers.
|
Artifact |
Notes |
|---|---|
|
Magic / XOR |
Gen-1: EVLCFG01 + key ev1lc0rp; Gen-2: SONOMAC1 + key sonomab |
|
Binary names |
dm5ne99sw9, aa9hb9425l (Gen-1 core name), pkgunpack, launcher, loader |
|
Bundle ID |
com.local.dm5ne99sw9 (core); builder may stamp lure IDs such as com.slack.installer.bld112 |
|
Temp / staging paths |
/tmp/.upd-*, /private/tmp/.upd-*, /tmp/.ldr-*, /tmp/.pkgunpack-*, /tmp/.eph-*.key / .pub, /tmp/.core-*.enc / .tar.gz, /tmp/.sys-%08x%08x (e.g. .sys-6df1ff3d0b8c2ce1), /tmp/.appbootstrap.* (Gen-1), /tmp/.sn-dropper-%u.lockdir, /tmp/.com.apple.install.log, /tmp/osalogging.zip |
|
Volume paths |
/Volumes/Toria-Installer/Toria.app, /Volumes/Slack/Slack.app |
|
Builder leak |
/var/www/evilcorp/backend/templates/macos/launcher.c |
|
Debug env |
LAUNCHER_DEBUG; log strings such as fetch: start / fetch: ok / fetch: failed |
Concise signals only, no reproduction playbook: