Reddit Scammers Spread AMOS and Lumma Stealer, Targeting Crypto Traders

21 March 2025 2 minutes Author: Newsman

Cybercriminals are using Reddit to spread the dangerous AMOS and Lumma Stealer viruses, luring victims with fake versions of TradingView. The main goal is to steal cryptocurrency wallets via infected files disguised as useful software.

The attackers create posts on cryptocurrency subreddits, offering “free lifetime access” to TradingView. They use fake websites and convincing answers to trick victims into downloading the infected archives.

– For Windows, Lumma Stealer is used, which is deployed via the malicious Costs.tiff.bat file, contacting a command-and-control server in Russia.

– For macOS, AMOS (Atomic Stealer) is distributed with a mechanism to scan for virtual machines to avoid analysis.

After infecting a device, the viruses steal cryptocurrency wallet data, user accounts, and distribute phishing links to their contacts.

AMOS and Lumma Stealer are well-known data-stealing programs that have been active since 2023. Fraudsters regularly use social networks and forums to distribute malware, including in the crypto community. Such campaigns have already emptied hundreds of wallets around the world.

Users should be wary of free software offers, especially if they are asked to disable antivirus or enter a password to unzip files. Software should be downloaded only from official sources, and cryptocurrency wallets should be protected with two-factor authentication.

Other related articles
News
Read more
New Cybercriminal Attacks Windows with Advanced Encryption and Detection Evasion
VanHelsing ransomware is a new powerful ransomware virus that targets Windows systems using a double ransom strategy. It encrypts data and steals confidential information for sale or disclosure. The virus uses modern detection evasion techniques, including rootkits, registry manipulation, and process injection. Victims communicate with hackers via Tor chat. Multi-layered cybersecurity, data backup, and timely system updates are recommended to protect against attacks.
124
News
Read more
Cloudflare Completely Blocks HTTP for APIs
Cloudflare is shutting down HTTP ports for api.cloudflare.com to address data leakage risks. HTTP blocking prevents interception of API tokens and sensitive information by ensuring a secure connection over HTTPS. This feature will be available to all Cloudflare customers in Q4 2025.
113
Found an error?
If you find an error, take a screenshot and send it to the bot.