logo

Hackers Use Fake TradingView Premium Posts on Reddit to Deliver Vidar and AMOS Stealers

ID: 6fe2408f-8c3b-5381-9034-9e6ce8c78d26

STIX ID: report--6fe2408f-8c3b-5381-9034-9e6ce8c78d26

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-07

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

Active Reddit-based campaign lures users with fake TradingView Premium downloads that deploy Vidar (Windows) and AMOS (macOS) infostealers; attackers use compromised business sites for hosting, null-byte PE padding, obfuscated batch scripts, and polymorphic Mach-O loaders to evade detection, rapidly swap domains and delete warnings, and exfiltrate browser credentials, session cookies, and cryptocurrency wallet files. Recommended defenses include blocking identified distribution domains, hunting for Reddit-to-large-ZIP download patterns, and monitoring the highlighted Windows and macOS process/command indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.