Lumma and AMOS are malware distributed via Reddit posts targeting Windows and Mac users in the crypto space.
Distribution Tactics on Reddit
Posts use various tactics to trick users into downloading infected software. A particularly common lure is a cracked version of TradingView.
Features of the Infected Software
These scammers are active on crypto-related subreddits. According to their posts, the cracked version is supposedly free and unlocks premium features such as advanced charting tools for stocks, forex, and crypto.
Technical Details on Mac and Windows
On Mac, user data is exfiltrated through a POST request to a server in Seychelles. On Windows, the malware loads via an obfuscated bat file linked to a host in Russia.
The distribution of Lumma and AMOS through Reddit highlights the need for careful attention to security, especially when dealing with unfamiliar software sources.