Friday, 19 December 2025
27.4 C
Singapore
29.2 C
Thailand
27.3 C
Indonesia
27.5 C
Philippines

Fake Reddit sites are delivering dangerous malware

Hackers use fake Reddit threads and WeTransfer sites to spread Lumma Stealer malware, targeting users with advanced data theft tactics.

According to a report from Bleeping Computer, hackers are spreading a harmful malware called Lumma Stealer by tricking you into clicking on links found in fake Reddit threads. These threads offer solutions to common problems but redirect you to fraudulent websites designed to mimic WeTransfer. Once on these fake sites, you may unknowingly download malicious files.

How the fake sites operate

Security researcher Crep1x from Sekoia.io uncovered nearly 1,000 fraudulent websites being used to spread the malware. Of these, 529 impersonate Reddit, while 407 mimic WeTransfer. To appear credible, these fake sites are crafted with domain names that combine random letters, numbers, and the brand name, typically ending in .org or .net.

A common tactic used by hackers involves creating a fake Reddit thread in which one user claims they need help downloading a specific tool. Another user responds, offering a WeTransfer link to the requested file along with a thank-you message to make it seem authentic. To create a sense of urgency, the post often mentions that the link will expire in two days.

When you click on the link, you are redirected to a website that looks almost identical to WeTransfer but is fake. Downloading the file leads to installing Lumma Stealer, which can compromise your personal information.

Why Lumma Stealer is dangerous

Lumma Stealer is highly advanced and designed to steal your data while avoiding detection. It has been distributed through several methods, including direct messages on social media, search engine optimisation (SEO) poisoning, malicious websites, and even deepfake nude generator sites.

Once the malware is downloaded, it can collect sensitive information, such as login credentials, payment details, and other personal data. The stolen information is then sent to the hackers, putting you at risk of identity theft and financial fraud.

Researcher Crep1x could not confirm precisely how victims initially encountered the fake links. However, the malware payload is hosted on a suspicious site called “weighcobbweo[.]top.”

How to protect yourself

To stay safe, avoid clicking on suspicious links, even if they seem to come from familiar platforms like Reddit or WeTransfer. Always double-check URLs for authenticity and ensure they match the official website’s domain. Installing reliable antivirus software is also essential to help detect and block malware threats.

Hackers continue to develop creative methods to spread malware like Lumma Stealer, so being cautious online is your best defence.

Hot this week

Dishonored and Deus Ex lead reflects on Arkane Austin’s closure

Harvey Smith reflects on Arkane Austin’s closure, Redfall’s challenges, and the human cost of layoffs in today’s games industry.

Plaud Note Pro launches in Singapore as AI-powered note-taking device

Plaud launches the Note Pro in Singapore, introducing a slim AI note-taker with real-time human-AI alignment and up to 50 hours of recording.

LG introduces Micro RGB evo TV ahead of CES 2026

LG unveils its first Micro RGB evo TV for CES 2026, promising wider colour gamut, higher brightness, and LCD performance closer to OLED.

Apple’s next AirTag could introduce major upgrades to tracking and battery features

Apple’s next AirTag may bring improved pairing, longer tracking range and better battery reporting, based on features found in iOS 26.

Tiiny AI unveils pocket-sized AI supercomputer verified by Guinness World Records

Tiiny AI reveals a Guinness-verified pocket-sized AI supercomputer designed to run massive models locally without relying on the cloud.

The rise of agentic AI and what it means for enterprise leaders

Agentic AI is accelerating across Asia, pushing leaders to rethink productivity, governance, and the infrastructure needed for long-term competitiveness.

Apple explores iPhone-class chip for future MacBook, leaks suggest

Leaked Apple files hint at testing a MacBook powered by an iPhone-class chip, suggesting a possible lower-cost laptop in the future.

Delta Electronics Singapore signs MOU with NUS to advance sustainable data centre innovation

Delta Electronics Singapore and NUS partner to develop sustainable, AI-ready data centre technologies for tropical environments.

Zoom introduces AI Companion 3.0 with a web-based assistant and expanded task automation

Zoom launches AI Companion 3.0, adding a web-based assistant that automates tasks, drafts emails and reshapes the platform into an AI workspace.

Related Articles

Popular Categories