- Security researchers discover hundreds of fake reddit and wetransfer pages
- These are used in a detailed scheme to implement the lumma -stealer
- The pages are well built and are probably distributed via SEO poisoning and malicious landing pages
There are hundreds of fake Reddit and Wetransfer places out there, all designed to trick people into downloading and running lumma stealer -malware, experts have warned.
CyberSecurity scientists from Sekoia have shared a complete list of pages on GitHub, which includes 59 false Reddit pages and 407 false Wetransfer pages.
The tactic is simple: The fake Reddit page shows a thread where a person asks help to find a specific piece of software. One of the answers shares a link to the fake Weransfer page where the tool can be downloaded. Other people in the thread share their thanks for the contribution and the discussion continues.
Targeting for forensic analysts
The researchers could not say for sure how victims end up on these pages, but it is safe to assume that there is a small SEO poisoning, malicious landing pages or communication with instant messaging.
The choice of fake software is also curious. Usually, these were researchers could find clues for who the goals are. If the striker is forged software development tools, the goals are DEVS. If they fall games, crypto -cartoons or discord clients, the goals are retail buyers in the web3 room.
In the example, Sekoia researchers shared, the striker went to OpentExt Encase Forensic – a tool used for scanning, collection and securing forensic data for law enforcement, government agency and business investigations. This is not exactly software that police, cybersecurity professional or businesses would pirate, nor do any average Internet users need.
Both the Reddit and Wetransfer pages were designed to look almost identical with the originals. Their URLs contain both brand names, followed by random numbers and characters. They are both at .org and .net-top-level domains, which further increases their legitimacy.
However, click the Download button on Wetransfer you lead to Lumma Stealer who hosts “Weighcobby[.]top.”
Via Bleeping computer