Thursday, 18 September 2025
32 C
Singapore
32.2 C
Thailand
29 C
Indonesia
28.5 C
Philippines

Fake Reddit sites are delivering dangerous malware

Hackers use fake Reddit threads and WeTransfer sites to spread Lumma Stealer malware, targeting users with advanced data theft tactics.

According to a report from Bleeping Computer, hackers are spreading a harmful malware called Lumma Stealer by tricking you into clicking on links found in fake Reddit threads. These threads offer solutions to common problems but redirect you to fraudulent websites designed to mimic WeTransfer. Once on these fake sites, you may unknowingly download malicious files.

How the fake sites operate

Security researcher Crep1x from Sekoia.io uncovered nearly 1,000 fraudulent websites being used to spread the malware. Of these, 529 impersonate Reddit, while 407 mimic WeTransfer. To appear credible, these fake sites are crafted with domain names that combine random letters, numbers, and the brand name, typically ending in .org or .net.

A common tactic used by hackers involves creating a fake Reddit thread in which one user claims they need help downloading a specific tool. Another user responds, offering a WeTransfer link to the requested file along with a thank-you message to make it seem authentic. To create a sense of urgency, the post often mentions that the link will expire in two days.

When you click on the link, you are redirected to a website that looks almost identical to WeTransfer but is fake. Downloading the file leads to installing Lumma Stealer, which can compromise your personal information.

Why Lumma Stealer is dangerous

Lumma Stealer is highly advanced and designed to steal your data while avoiding detection. It has been distributed through several methods, including direct messages on social media, search engine optimisation (SEO) poisoning, malicious websites, and even deepfake nude generator sites.

Once the malware is downloaded, it can collect sensitive information, such as login credentials, payment details, and other personal data. The stolen information is then sent to the hackers, putting you at risk of identity theft and financial fraud.

Researcher Crep1x could not confirm precisely how victims initially encountered the fake links. However, the malware payload is hosted on a suspicious site called “weighcobbweo[.]top.”

How to protect yourself

To stay safe, avoid clicking on suspicious links, even if they seem to come from familiar platforms like Reddit or WeTransfer. Always double-check URLs for authenticity and ensure they match the official website’s domain. Installing reliable antivirus software is also essential to help detect and block malware threats.

Hackers continue to develop creative methods to spread malware like Lumma Stealer, so being cautious online is your best defence.

Hot this week

Apple says software updates may cause short-term dips in battery life and performance

Apple explains why software updates may briefly affect battery life and performance, highlighting long-term benefits for security and features.

Devialet launches Phantom Ultimate, a new generation of high-end sound

Devialet introduces Phantom Ultimate, its latest high-end wireless speaker, combining advanced engineering, French design, and new finishes.

Apple brings major upgrades to Powerbeats Pro 2 with iOS 26

Apple adds heart rate, fitness, and smart usability upgrades to Powerbeats Pro 2 with iOS 26, launching on 15 September.

Southeast Asia startup funding sinks to six-year low as investors turn selective

Startup funding in Southeast Asia fell to a six-year low in H1 2025, though Vietnam, Malaysia and late-stage deals showed resilience.

China’s retail market shifts as instant commerce rivalry intensifies

China’s retail market is being reshaped as Alibaba, Meituan and JD.com battle for dominance in instant commerce with fast, low-cost deliveries.

Half of Singapore workers face financial strain as demand for pay flexibility rises

Half of Singapore’s workforce is financially vulnerable, with rising demand for flexible pay and payroll teams struggling under mounting pressure.

IBS Software and Emirates Skywards launch new loyalty platform partnership

IBS Software and Emirates Skywards launch iLoyal, a next-gen loyalty platform serving 35 million members with enhanced digital experiences.

GitLab survey shows AI software innovation could unlock over S$6 billion in Singapore

GitLab survey finds AI software innovation could generate over S$6 billion annually in Singapore, with skills and governance key to success.

New Relic study shows IT outages cost Southeast Asian firms up to US$165.5 million a year

A New Relic report finds IT outages cost Southeast Asian firms up to US$165.5m yearly, with AI driving demand for observability.

Related Articles

Popular Categories