ALERT: Crypto Wallets Emptied as Fake TradingView Premium Apps Spread Malware Through Reddit

  • Malware-infected “cracked” versions of TradingView Premium are being distributed on Reddit cryptocurrency forums.
  • The malware variants (Lumma Stealer for Windows and AMOS for Mac) steal crypto wallet credentials, passwords, and 2FA information.
  • Scammers actively engage with potential victims, even providing instructions to bypass Mac security measures.

Cryptocurrency users are being targeted by sophisticated malware disguised as free “cracked” versions of TradingView Premium, resulting in complete wallet drains and identity theft. The malicious software, being distributed primarily through Reddit cryptocurrency communities, contains data-stealing payloads that capture sensitive wallet information and authentication credentials.

- Advertisement -

Security researchers at Malwarebytes have identified two distinct malware variants deployed in this campaign: Lumma Stealer targeting Windows users and Atomic Stealer (AMOS) focusing on Mac systems. Both variants are specifically designed to exfiltrate cryptocurrency credentials and bypass security measures.

“What’s interesting with this particular scheme is how involved the original poster is,” noted Jérôme Segura, a senior security researcher at Malwarebytes, in a blog post analyzing the attack.

The operation demonstrates unusual persistence, with attackers actively engaging potential victims through Reddit comments. These bad actors pose as helpful community members, providing step-by-step instructions to circumvent critical security protections. In one documented case, a scammer advised a user: “That ‘Apple could not verify’ warning is just Apple being extra cautious… Don’t worry, though – a real virus on a Mac would be wild, and I’ve never seen one sneak through like that!”

Technical analysis of the AMOS malware shows it transmits stolen data to servers based in the Seychelles. The information captured includes passwords, two-factor authentication codes, and cryptocurrency wallet credentials. The Lumma Stealer variant, which has been active since 2022, specifically targets cryptocurrency wallets and browser extensions used for two-factor authentication.

- Advertisement -

The attack doesn’t en

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Tesla Shares Slip After USPTO Blocks Cybercab, Robotaxi Name

Tesla shares dipped after the United States Patent and Trademark Office denied trademark applications...

Elon Musk’s xAI Raises $20B; Valuation Still Undisclosed Now

xAI raised $20 billion in an upsized Series E, surpassing a prior $15 billion...

Riot sells 2,201 BTC for $200M to fund AI data center build.

Riot Platforms sold 2,201 BTC across November and December, raising nearly $200 million in...

Aave v4 and Lido v3 Spark Major DeFi Upgrades, 2026 Outlook!

Major DeFi protocols plan substantive upgrades in early 2026.Aave is preparing a new architecture...

Hyperliquid Unlock Dilutes HYPE Holders by $331M amid $268M+

Hyperliquid unlocked 12,457,813 HYPE tokens from a founding vesting allocation, increasing circulating supply by...
- Advertisement -

Must Read

What is Moon Tropica (CAH) – Technology, Tokenomics, Game Preview

Gaming enthusiasts and crypto enthusiasts, hHave you heard about Moon Tropica? If you're longing for that nostalgic feel of classic games from your childhood...
Bitcoin (BTC) $ 93,641.00 0.34%
Ethereum (ETH) $ 3,291.57 1.92%
XRP (XRP) $ 2.30 2.13%
Bittensor (TAO) $ 293.54 9.55%
Polkadot (DOT) $ 2.23 1.14%
Cardano (ADA) $ 0.418988 0.59%
Chainlink (LINK) $ 14.02 0.66%
Hyperliquid (HYPE) $ 28.22 6.41%
Monero (XMR) $ 442.07 1.36%
Hedera (HBAR) $ 0.128796 2.66%
Toncoin (TON) $ 1.90 0.00%