Around 1,000 websites that mimic Reddit and the file-sharing service WeTransfer are distributing the Lumma Stealer malware.

Attackers are abusing the Reddit brand by displaying a fake discussion thread about a specific topic. In this discussion, the thread creator asks for help downloading a tool and another user supposedly uploads that tool to WeTransfer, sharing the link. Finally, a third user appears in the discussion thanking him for the link.
See also: Google: Fake Homebrew ads distribute infostealer
Unsuspecting victims who see the conversation click on the link to the supposed tool and are taken to a website WeTransfer that mimics the service's interface. If the victim clicks on the "Download" button to download the tool, the Lumma Stealer malware will be downloaded.
All of the websites used in this campaign contain a string of the brand they are impersonating, followed by random numbers and characters. At first glance, they appear legitimate. The top-level domains are either “.org” or “.net”.
The fake Reddit and WeTransfer impersonation websites were spotted by Sekoia researcher crep1x, who shared a full list. In total, there are 529 Reddit impersonation pages and 407 WeTransfer impersonation pages that lead to the download of the Lumma Stealer malware.
The attack can be initiated through various methods: malvertising, SEO poisoning, malicious websites, direct messages on social media, and more.
See also: GitHub: Fake PoC exploit for infostealer vulnerability is being distributed
A year ago, the same researcher discovered a similar campaign where 1,300 websites abused AnyDesk to promote the Vidar Stealer malware.
As for the new campaign, Lumma Stealer is a powerful data theft. It is sold to hackers who distribute it through various methods. It can collect, among other things, passwords stored in web browsers and session tokens that can be used to compromise accounts.

Protection from info-stealer malware
Static detection methods for security are not enough to avoid software antivirus malware . A more robust approach should incorporate , equipped with advanced analysis capabilities.
It's also important to keep your operating system and applications up to date. These updates often include security that can protect your computer from the latest threats.
Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks , which attackers often use to install info-stealers (e.g. Lumma Stealer).
See also: Beware! New malware campaign distributes Skuld info-stealer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users to avoid executable files downloaded from strange websites.
Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to your account, even if they manage to steal your password.
Source: www.bleepingcomputer.com
