According to TechRadar , cybersecurity experts at Sekoia have just discovered hundreds of fake Reddit and WeTransfer websites designed to spread the Lumma Stealer malware. This type of malware is capable of stealing sensitive information such as passwords, financial data, and personal information.
Reddit has been impersonated to spread malware that steals data.
Sophisticated scam impersonating Reddit
Accordingly, hackers created numerous fake threads on Reddit where users asked about a specific software, and the perpetrators would post links to a fake WeTransfer page containing malware disguised as legitimate software.
Notably, the fake software used in this campaign was OpenText Encase Forensic, a specialized tool for digital analysis. This suggests the perpetrators may be targeting law enforcement agencies, cybersecurity professionals, or businesses.
The interface of a fake Reddit page with a misleading URL.
IMAGE: SCREENSHOT FROM BLEEPING COMPUTER
Both the fake Reddit and WeTransfer sites are designed to look very similar to the real websites, using both .org and .net domain names to increase credibility. However, the download links on the fake WeTransfer site will lead to the Lumma Stealer malware.
Sekoia has now published a list of fake websites on GitHub to warn users, which can be found at tinyurl.com/fakeredditsusites .
To avoid becoming a victim of this scam, people need to be wary of software download links from unknown sources, especially on social media, and always double-check the URL before clicking on any link.
Source: https://thanhnien.vn/phat-hien-dien-dan-reddit-gia-mao-phat-tan-ma-doc-185250124225625762.htm








Comment (0)