Friday, 28 February 2025
26.7 C
Singapore
31.8 C
Thailand
20.6 C
Indonesia
26.3 C
Philippines

Fake Reddit sites are delivering dangerous malware

Hackers use fake Reddit threads and WeTransfer sites to spread Lumma Stealer malware, targeting users with advanced data theft tactics.

According to a report from Bleeping Computer, hackers are spreading a harmful malware called Lumma Stealer by tricking you into clicking on links found in fake Reddit threads. These threads offer solutions to common problems but redirect you to fraudulent websites designed to mimic WeTransfer. Once on these fake sites, you may unknowingly download malicious files.

How the fake sites operate

Security researcher Crep1x from Sekoia.io uncovered nearly 1,000 fraudulent websites being used to spread the malware. Of these, 529 impersonate Reddit, while 407 mimic WeTransfer. To appear credible, these fake sites are crafted with domain names that combine random letters, numbers, and the brand name, typically ending in .org or .net.

A common tactic used by hackers involves creating a fake Reddit thread in which one user claims they need help downloading a specific tool. Another user responds, offering a WeTransfer link to the requested file along with a thank-you message to make it seem authentic. To create a sense of urgency, the post often mentions that the link will expire in two days.

When you click on the link, you are redirected to a website that looks almost identical to WeTransfer but is fake. Downloading the file leads to installing Lumma Stealer, which can compromise your personal information.

Why Lumma Stealer is dangerous

Lumma Stealer is highly advanced and designed to steal your data while avoiding detection. It has been distributed through several methods, including direct messages on social media, search engine optimisation (SEO) poisoning, malicious websites, and even deepfake nude generator sites.

Once the malware is downloaded, it can collect sensitive information, such as login credentials, payment details, and other personal data. The stolen information is then sent to the hackers, putting you at risk of identity theft and financial fraud.

Researcher Crep1x could not confirm precisely how victims initially encountered the fake links. However, the malware payload is hosted on a suspicious site called “weighcobbweo[.]top.”

How to protect yourself

To stay safe, avoid clicking on suspicious links, even if they seem to come from familiar platforms like Reddit or WeTransfer. Always double-check URLs for authenticity and ensure they match the official website’s domain. Installing reliable antivirus software is also essential to help detect and block malware threats.

Hackers continue to develop creative methods to spread malware like Lumma Stealer, so being cautious online is your best defence.

Hot this week

ST Telemedia Global Data Centres begins construction on Johor data centre, partners with Johor Talent Development Council

STT GDC breaks ground on a high-performance computing data centre in Johor, focusing on sustainability and talent development with JTDC.

Mobile Legends: Bang Bang added to 2026 Asian Games as esports lineup expands

Mobile Legends: Bang Bang will be a medalled event at the 2026 Asian Games, joining a growing esports lineup at the international competition.

Federal agency to deactivate charging stations and offload electric vehicles

The GSA is shutting down its EV chargers nationwide, calling them “not mission critical,” and plans to offload newly purchased electric vehicles.

Taiwan’s chipmakers weigh U.S. factories to sidestep tariffs

Taiwan’s chipmakers face a tough choice: build costly U.S. factories or absorb high tariffs as Trump pushes for local semiconductor production.

Hyundai’s NACS port faces a major issue at Tesla charging stations

The 2025 Hyundai Ioniq 5’s new Tesla charging port faces real-world challenges due to its placement. Find out how this affects EV owners.

Twitch expands monetisation tools to more streamers

Twitch is expanding its monetisation tools, allowing more streamers to earn through subscriptions and Bits while improving mobile features.

Meta cracks down on leaks, fires 20 employees

Meta has fired around 20 employees for leaking confidential information following an investigation into reports exposing internal meetings and plans.

Meta prepares to launch a separate app for its AI assistant

Meta is reportedly developing a standalone AI chatbot app and testing a paid subscription model to expand its AI offerings.

Passport-free travel and the future of global airport security

Discover how biometric technology is transforming global airport security, streamlining travel, and addressing challenges in a passport-free future.

Related Articles

Popular Categories