Hackers Use Fake TradingView Premium Posts on Reddit to Deliver Vidar and AMOS Stealers
ID: 6fe2408f-8c3b-5381-9034-9e6ce8c78d26
STIX ID: report--6fe2408f-8c3b-5381-9034-9e6ce8c78d26
Feed Name: cybersecurityNews.com
Active Reddit-based campaign lures users with fake TradingView Premium downloads that deploy Vidar (Windows) and AMOS (macOS) infostealers; attackers use compromised business sites for hosting, null-byte PE padding, obfuscated batch scripts, and polymorphic Mach-O loaders to evade detection, rapidly swap domains and delete warnings, and exfiltrate browser credentials, session cookies, and cryptocurrency wallet files. Recommended defenses include blocking identified distribution domains, hunting for Reddit-to-large-ZIP download patterns, and monitoring the highlighted Windows and macOS process/command indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
