Hackers Exploit Reddit to Spread Crypto-Stealing Malware

Listen to this Post

Malicious TradingView Cracks Used to Target Crypto Users

Cybercriminals are taking advantage of Reddit’s vast user base to distribute malware aimed at cryptocurrency enthusiasts. They are disguising their attacks as cracked versions of TradingView, a popular trading platform, tricking unsuspecting users into downloading malicious software. Two major malware families—AMOS and Lumma stealers—are being spread through this scheme, designed to steal sensitive user data and empty crypto wallets.

How the Malware is Distributed

Unlike traditional malware campaigns that rely on file-sharing services like Mega, these attackers are using a website belonging to a Dubai-based cleaning company to host their malicious files. This unusual tactic allows them to maintain greater control over their payloads and push updates as needed.

The malware is distributed as double-zipped files, with the final layer being password-protected—an evasion technique that helps bypass security scanners. Legitimate software rarely follows such a distribution method, making this a significant red flag.

On Mac systems, the malware is a variant of the AMOS stealer, which checks whether it is running in a virtual machine (a common analysis environment used by security researchers). If a VM is detected, the malware shuts down immediately. If not, it exfiltrates sensitive data via a POST request to a server hosted in the Seychelles.

For Windows users, the malware arrives through an obfuscated batch file, executing a malicious AutoIt script. Its command-and-control server is registered in Russia, allowing the attackers to remotely control infected systems and steal cryptocurrency funds.

The Devastating Impact on Victims

Those who fall for this scam have reported severe financial losses, with emptied cryptocurrency wallets and stolen personal data. Additionally, attackers use compromised accounts to send phishing links to victims’ contacts, further spreading the infection.

How to Stay Safe

To protect yourself from these threats:

  • Be wary of password-protected files—legitimate software rarely requires this.
  • Avoid downloading from unofficial sources, even if the link is shared by a trusted Reddit user.
  • Use reputable cybersecurity tools like Malwarebytes, which can detect and remove these threats on both Windows and macOS.
  • Keep security software enabled, as disabling it can leave your system vulnerable to these attacks.

Even with these precautions, the risk remains, especially when scams originate from seemingly trusted sources. Vigilance is key to avoiding cybercriminal traps.

What Undercode Say:

The use of Reddit as a distribution channel highlights a growing trend in cybercrime: leveraging trusted community platforms to spread malware. Here’s a deeper look at what makes this attack method so effective and dangerous.

1. Exploiting Trust in Online Communities

Cybercriminals know that Reddit users often share software recommendations and trading tools. By posting in forums frequented by cryptocurrency enthusiasts, they gain credibility and increase the likelihood of users falling for their scam.

2. The Clever Use of a Legitimate Website

Rather than using well-known file-sharing services, attackers are hosting malware on a Dubai-based cleaning company’s website. This helps them avoid detection, as security tools are less likely to flag an unfamiliar, seemingly harmless domain.

3. The Password-Protected File Strategy

Most security scanners struggle with password-protected files, as they cannot analyze the contents before execution. This is a common evasion tactic used by malware authors to slip past antivirus defenses.

4. Cross-Platform Threats

Many malware campaigns target either Windows or macOS, but this attack deploys versions for both operating systems. This broadens the attack surface, increasing the number of potential victims.

5. Advanced Evasion Techniques

The Mac version of the malware detects virtual machines to avoid analysis by security researchers. This level of sophistication suggests the work of experienced cybercriminals rather than amateur hackers.

6. Links to Russia and Seychelles

The infrastructure behind the malware—command-and-control servers in Russia and data exfiltration points in the Seychelles—indicates a well-planned, international operation. This is not a small-scale scam but a coordinated attack with significant resources behind it.

7. Social Engineering at Play

Victims are often tricked through social engineering, as attackers impersonate compromised users to spread phishing links. This technique makes the scam more effective by exploiting personal trust networks.

8. Financial Consequences

Beyond immediate cryptocurrency theft, compromised systems may also leak sensitive financial information, potentially leading to identity theft or further financial fraud.

9. The Need for Community Awareness

While cybersecurity tools can help detect threats, community awareness is crucial. Users need to recognize warning signs—such as unusual file-sharing methods and too-good-to-be-true software offers—to prevent falling victim.

10. What This Means for Cybersecurity

This case underscores the evolving nature of cyber threats. Attackers are no longer relying solely on traditional phishing emails or malicious websites; they are actively infiltrating trusted online spaces. This calls for stronger security policies on platforms like Reddit and increased vigilance among users.

Fact Checker Results:

🔹 Malware delivery through Reddit is a confirmed trend, with multiple reports documenting similar tactics.
🔹 Password-protected malware files are a common evasion technique, but security tools can detect them with heuristic analysis.
🔹 The involvement of Russian and Seychelles-based servers aligns with previous cybercrime patterns, often linked to organized hacking groups.

References:

Reported By: https://cyberpress.org/threat-actors-exploit-reddit-to-distribute-amos/
Extra Source Hub:
https://www.stackexchange.com
Wikipedia
Undercode AI

Image Source:

Pexels
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 TelegramFeatured Image