logo

Fake TradingView Premium Reddit Posts Spread Vidar and AMOS Stealers

ID: 2639b57d-68df-517f-b8e8-2632f440e0a0

STIX ID: report--2639b57d-68df-517f-b8e8-2632f440e0a0

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

A coordinated campaign is abusing Reddit to distribute fake "TradingView Premium" installers that install Vidar on Windows and AMOS on macOS; operators use compromised business domains, password-protected and nested archives, large padded installers, and likely purchased or hijacked Reddit accounts to evade detection and simulate legitimacy. The report details artifacts and behaviors (archive passwords like "github", wextract-based reconstruction on Windows, universal Mach-O binaries and osascript usage on macOS), lists observed distribution domains and paths, and recommends blocking domains, monitoring for large downloads after Reddit sessions, and endpoint detections for wextract/cmd.exe on Windows and unsigned macOS apps invoking osascript or unusual HTTP POST traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.