logo

AMOS and Lumma stealers actively spread to Reddit users

ID: 25c6bf1f-fe1a-54ea-ac28-804d8e9f9113

STIX ID: report--25c6bf1f-fe1a-54ea-ac28-804d8e9f9113

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2025-03-18

Date Updated: 2026-04-28

...
...

Malicious actors are distributing Windows and macOS stealers (Lumma and AMOS/Atomic) through official Reddit posts offering cracked TradingView installers; the campaign uses double-zipped, password-protected archives and obfuscated loaders, contacts a Seychelles IP (45.140.13.244) and a recently registered C2 domain (cousidporke.icu), and has been reported to drain victims' cryptocurrency wallets and reuse their identities to phish contacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.