ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

Fake Reddit and WeTransfer Sites Are Pushing Malware

mediumMalwareimportance 30

Indicators of compromiseAll →

TypeIndicatorContext
domainweighcobbweo.topnload’ button leads to the Lumma Stealer payload hosted on “weighcobbweo[.]top.” Boing Boing post . Tags: malware Posted on January 30,
Full article85 words · extracted from schneier.com · click to collapse

There are thousands of fake Reddit and WeTransfer webpages that are pushing malware. They exploit people who are using search engines to search sites like Reddit.

Unsuspecting victims clicking on the link are taken to a fake WeTransfer site that mimicks the interface of the popular file-sharing service. The ‘Download’ button leads to the Lumma Stealer payload hosted on “weighcobbweo[.]top.”

Boing Boing post.

Tags: malware

Posted on January 30, 2025 at 7:44 AM4 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2025/01/fake-reddit-and-wetransfer-sites-are-pushing-malware.html