HomeSecurityFake Reddit and WeTransfer pages distribute Lumma Stealer malware

Fake Reddit and WeTransfer pages distribute Lumma Stealer malware

Around 1,000 websites that mimic Reddit and the file-sharing service WeTransfer are distributing the Lumma Stealer malware.

Lumma Stealer malware Reddit and WeTransfer

Attackers are abusing the Reddit brand by displaying a fake discussion thread about a specific topic. In this discussion, the thread creator asks for help downloading a tool and another user supposedly uploads that tool to WeTransfer, sharing the link. Finally, a third user appears in the discussion thanking him for the link.

See also: Google: Fake Homebrew ads distribute infostealer

Unsuspecting victims who see the conversation click on the link to the supposed tool and are taken to a website WeTransfer that mimics the service's interface. If the victim clicks on the "Download" button to download the tool, the Lumma Stealer malware will be downloaded.

All of the websites used in this campaign contain a string of the brand they are impersonating, followed by random numbers and characters. At first glance, they appear legitimate. The top-level domains are either “.org” or “.net”.

The fake Reddit and WeTransfer impersonation websites were spotted by Sekoia researcher crep1x, who shared a full list. In total, there are 529 Reddit impersonation pages and 407 WeTransfer impersonation pages that lead to the download of the Lumma Stealer malware.

The attack can be initiated through various methods: malvertising, SEO poisoning, malicious websites, direct messages on social media, and more.

See also: GitHub: Fake PoC exploit for infostealer vulnerability is being distributed

A year ago, the same researcher discovered a similar campaign where 1,300 websites abused AnyDesk to promote the Vidar Stealer malware.

As for the new campaign, Lumma Stealer is a powerful data theft. It is sold to hackers who distribute it through various methods. It can collect, among other things, passwords stored in web browsers and session tokens that can be used to compromise accounts.

Fake Reddit and WeTransfer pages distribute Lumma Stealer malware

Protection from info-stealer malware

Static detection methods for security are not enough to avoid software antivirus malware . A more robust approach should incorporate , equipped with advanced analysis capabilities.

It's also important to keep your operating system and applications up to date. These updates often include security that can protect your computer from the latest threats.

Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks , which attackers often use to install info-stealers (e.g. Lumma Stealer).

See also: Beware! New malware campaign distributes Skuld info-stealer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users to avoid executable files downloaded from strange websites.

Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to your account, even if they manage to steal your password.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS