{"id":11914,"date":"2026-04-07T10:03:36","date_gmt":"2026-04-07T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/07\/hackers-use-fake-tradingview-premium-posts-on-reddit-to-deliver-vidar-and-amos-stealers\/"},"modified":"2026-04-07T10:03:36","modified_gmt":"2026-04-07T10:03:36","slug":"hackers-use-fake-tradingview-premium-posts-on-reddit-to-deliver-vidar-and-amos-stealers","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/07\/hackers-use-fake-tradingview-premium-posts-on-reddit-to-deliver-vidar-and-amos-stealers\/","title":{"rendered":"Hackers Use Fake TradingView Premium Posts on Reddit to Deliver Vidar and AMOS Stealers"},"content":{"rendered":"<p>    Hackers Use Fake TradingView Premium Posts on Reddit to Deliver Vidar and AMOS Stealers<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A threat actor has been running an active campaign on Reddit, using fake posts that promise free TradingView Premium access to deliver two malware families \u2014 Vidar on Windows and AMOS on macOS. The operation is still live, with new posts surfacing as older ones get taken down.<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/c61511c8-5b48-48f5-8821-2f162ef6d6ba\/Hackers-Use-Fake-TradingView-Premium-Posts-on-Reddit-to-Deliver-Vidar-and-AMOS-Stealers.pdf?AWSAccessKeyId=ASIA2F3EMEYEZZ4KAVWO&amp;Signature=7k%2FaPqhNW1rDtXJvT5YO3c3VkNI%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEBYaCXVzLWVhc3QtMSJIMEYCIQDlnR4flq5VG%2FqXubRY43w8fPi420%2BkjRT8bDba5DJ%2B%2BQIhALMHFO1VKhSUgI2U%2BJ%2FCs01b5rKew5abzyYQg2kX%2Bv%2FQKvwECN7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgxttiYdBRhAdUhcAk4q0AQZKQrMXE0rSKjVEREqeJTffq3ZvbMI%2FMgktV0yw9SiZ%2BjWFeGnaTHiFZfcuLTGrXk3Q%2B8VMpmUzzRraQC1GsfUdrUb9sC0mfhANvwTDnwL%2Fp6Ao0ZULCn6iZbE2GgMQSUGgdzGxwWcktUxWOKr%2BjzBPhsIevzqnRxeuOOqLVbcJgJulc8sYaQw2rRjQTT8ZhdoLPjnwLa30biFQHUaC2l30tOj%2B8n5wStIjydCLNA8wcwpDMmLrober%2FUoWyRWuTHTiOwFEoR6irTCQa5bQWn20QTuee7rc9nxXoIchwMiE4qDIful1KkdUTXywm7fa7xdw07NdM7SZE80R9319ecqpX3pxqk%2FmSIovCZS7BeFBZNFADjEUKzlIyGxRk6hCBHbokXBIJA%2ByYqkS9aw24PK%2B9%2Bn0OXe8Kw8jt8COgoNds%2BrGRkLPISDsyLaZwm%2F85lzy%2BjO50JNhX3HW59sogFlMZTCSGAiSoFEjN%2F4vouo0WkhtnopcPIvjnzwg%2FYFu6sEUG%2FjuSVQIIneOXWn64kuNmBmAv2JzVyZjVJkoejUVRaJeorMWuhwNT33UV%2BLBeF6usSvN3pYlLFl3MnV4b%2B2lV139L3LuuvXwM2xakRquzJCm4GCDYcVRNcbUwr8qK%2FPaeVtKZ9zD78NyPvimgjPeXvPM46xcwKdqBs49t4J92b1ZWx23IaDYqgUp8xK7VmNYbczLy%2BwbRHFGWD0r%2BrrQ44Nt6TRPhYetFTIyT%2BSsFouwSqDx1%2FiB5X1wfJDkkwMo0X0fsXZKPr2JX3dmo9kMK%2Bj0s4GOpcBNTLUBpOMTKE4C1radSZ5%2B5mOhGSv7hsA7wSWN7ufzaEp%2FDoFfXDfZxRxRVNqX2QMBitz1XjdOneBBBsAdgx1vVkHnDTRCgHpKuCzgLG6BCvzBdd9VEsmX6QIXbC8sIps7Qm8fOwyvY9%2F3B4lhlkoq0ZPs%2B1XntWwsm2AGJdZCksi6q9f%2BZPY4wSVNrM0mwKcDvgCkpo9GA%3D%3D&amp;Expires=1775541451\"><\/a><\/p>\n<p>TradingView is one of the most widely used charting platforms among retail traders, crypto investors, and forex enthusiasts. Its Premium subscription unlocks advanced indicators and real-time market data at a price many users would rather skip. <\/p>\n<p>The threat actor exploits that gap by posting across multiple subreddits \u2014 some hijacked, others purpose-built \u2014 with step-by-step instructions that walk victims through the full infection chain without raising suspicion.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/c61511c8-5b48-48f5-8821-2f162ef6d6ba\/Hackers-Use-Fake-TradingView-Premium-Posts-on-Reddit-to-Deliver-Vidar-and-AMOS-Stealers.pdf?AWSAccessKeyId=ASIA2F3EMEYEZZ4KAVWO&amp;Signature=7k%2FaPqhNW1rDtXJvT5YO3c3VkNI%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEBYaCXVzLWVhc3QtMSJIMEYCIQDlnR4flq5VG%2FqXubRY43w8fPi420%2BkjRT8bDba5DJ%2B%2BQIhALMHFO1VKhSUgI2U%2BJ%2FCs01b5rKew5abzyYQg2kX%2Bv%2FQKvwECN7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgxttiYdBRhAdUhcAk4q0AQZKQrMXE0rSKjVEREqeJTffq3ZvbMI%2FMgktV0yw9SiZ%2BjWFeGnaTHiFZfcuLTGrXk3Q%2B8VMpmUzzRraQC1GsfUdrUb9sC0mfhANvwTDnwL%2Fp6Ao0ZULCn6iZbE2GgMQSUGgdzGxwWcktUxWOKr%2BjzBPhsIevzqnRxeuOOqLVbcJgJulc8sYaQw2rRjQTT8ZhdoLPjnwLa30biFQHUaC2l30tOj%2B8n5wStIjydCLNA8wcwpDMmLrober%2FUoWyRWuTHTiOwFEoR6irTCQa5bQWn20QTuee7rc9nxXoIchwMiE4qDIful1KkdUTXywm7fa7xdw07NdM7SZE80R9319ecqpX3pxqk%2FmSIovCZS7BeFBZNFADjEUKzlIyGxRk6hCBHbokXBIJA%2ByYqkS9aw24PK%2B9%2Bn0OXe8Kw8jt8COgoNds%2BrGRkLPISDsyLaZwm%2F85lzy%2BjO50JNhX3HW59sogFlMZTCSGAiSoFEjN%2F4vouo0WkhtnopcPIvjnzwg%2FYFu6sEUG%2FjuSVQIIneOXWn64kuNmBmAv2JzVyZjVJkoejUVRaJeorMWuhwNT33UV%2BLBeF6usSvN3pYlLFl3MnV4b%2B2lV139L3LuuvXwM2xakRquzJCm4GCDYcVRNcbUwr8qK%2FPaeVtKZ9zD78NyPvimgjPeXvPM46xcwKdqBs49t4J92b1ZWx23IaDYqgUp8xK7VmNYbczLy%2BwbRHFGWD0r%2BrrQ44Nt6TRPhYetFTIyT%2BSsFouwSqDx1%2FiB5X1wfJDkkwMo0X0fsXZKPr2JX3dmo9kMK%2Bj0s4GOpcBNTLUBpOMTKE4C1radSZ5%2B5mOhGSv7hsA7wSWN7ufzaEp%2FDoFfXDfZxRxRVNqX2QMBitz1XjdOneBBBsAdgx1vVkHnDTRCgHpKuCzgLG6BCvzBdd9VEsmX6QIXbC8sIps7Qm8fOwyvY9%2F3B4lhlkoq0ZPs%2B1XntWwsm2AGJdZCksi6q9f%2BZPY4wSVNrM0mwKcDvgCkpo9GA%3D%3D&amp;Expires=1775541451\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p><a href=\"https:\/\/hexastrike.com\/resources\/blog\/threat-intelligence\/reddit-tradingview-lures-leading-to-vidar-and-amos-stealers\/\" id=\"https:\/\/hexastrike.com\/resources\/blog\/threat-intelligence\/reddit-tradingview-lures-leading-to-vidar-and-amos-stealers\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Hexastrike analysts traced these infections<\/a> back to Reddit while handling several recent stealer cases. <\/p>\n<p>They identified a single threat actor operating across at least five subreddits, using aged, purchased, or compromised accounts to appear credible. <\/p>\n<p>What stands out is not technical complexity but operational discipline \u2014 hosting domains get swapped the moment they are flagged, warning comments from real users are deleted within minutes, and the posts appear LLM-generated to keep a consistent tone.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/c61511c8-5b48-48f5-8821-2f162ef6d6ba\/Hackers-Use-Fake-TradingView-Premium-Posts-on-Reddit-to-Deliver-Vidar-and-AMOS-Stealers.pdf?AWSAccessKeyId=ASIA2F3EMEYEZZ4KAVWO&amp;Signature=7k%2FaPqhNW1rDtXJvT5YO3c3VkNI%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEBYaCXVzLWVhc3QtMSJIMEYCIQDlnR4flq5VG%2FqXubRY43w8fPi420%2BkjRT8bDba5DJ%2B%2BQIhALMHFO1VKhSUgI2U%2BJ%2FCs01b5rKew5abzyYQg2kX%2Bv%2FQKvwECN7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgxttiYdBRhAdUhcAk4q0AQZKQrMXE0rSKjVEREqeJTffq3ZvbMI%2FMgktV0yw9SiZ%2BjWFeGnaTHiFZfcuLTGrXk3Q%2B8VMpmUzzRraQC1GsfUdrUb9sC0mfhANvwTDnwL%2Fp6Ao0ZULCn6iZbE2GgMQSUGgdzGxwWcktUxWOKr%2BjzBPhsIevzqnRxeuOOqLVbcJgJulc8sYaQw2rRjQTT8ZhdoLPjnwLa30biFQHUaC2l30tOj%2B8n5wStIjydCLNA8wcwpDMmLrober%2FUoWyRWuTHTiOwFEoR6irTCQa5bQWn20QTuee7rc9nxXoIchwMiE4qDIful1KkdUTXywm7fa7xdw07NdM7SZE80R9319ecqpX3pxqk%2FmSIovCZS7BeFBZNFADjEUKzlIyGxRk6hCBHbokXBIJA%2ByYqkS9aw24PK%2B9%2Bn0OXe8Kw8jt8COgoNds%2BrGRkLPISDsyLaZwm%2F85lzy%2BjO50JNhX3HW59sogFlMZTCSGAiSoFEjN%2F4vouo0WkhtnopcPIvjnzwg%2FYFu6sEUG%2FjuSVQIIneOXWn64kuNmBmAv2JzVyZjVJkoejUVRaJeorMWuhwNT33UV%2BLBeF6usSvN3pYlLFl3MnV4b%2B2lV139L3LuuvXwM2xakRquzJCm4GCDYcVRNcbUwr8qK%2FPaeVtKZ9zD78NyPvimgjPeXvPM46xcwKdqBs49t4J92b1ZWx23IaDYqgUp8xK7VmNYbczLy%2BwbRHFGWD0r%2BrrQ44Nt6TRPhYetFTIyT%2BSsFouwSqDx1%2FiB5X1wfJDkkwMo0X0fsXZKPr2JX3dmo9kMK%2Bj0s4GOpcBNTLUBpOMTKE4C1radSZ5%2B5mOhGSv7hsA7wSWN7ufzaEp%2FDoFfXDfZxRxRVNqX2QMBitz1XjdOneBBBsAdgx1vVkHnDTRCgHpKuCzgLG6BCvzBdd9VEsmX6QIXbC8sIps7Qm8fOwyvY9%2F3B4lhlkoq0ZPs%2B1XntWwsm2AGJdZCksi6q9f%2BZPY4wSVNrM0mwKcDvgCkpo9GA%3D%3D&amp;Expires=1775541451\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The subreddits tell a clear story. r\/BitBullito and r\/CryptoCurrencyDM had just two and 29 subscribers respectively, while the accounts posting in them were three to six years old \u2014 lending false legitimacy to the operation. <\/p>\n<p>One account, u\/BroadDepartment573, carried a Four Year Club Reddit trophy but had only a single post across its entire history.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPXXzp2roAKjDeuKKPGj_G41wCA0Hxk97M_ZefSClREdfHfeKNyEkx4ISwwtZrjYS2srbcGuZjVWfzrLzrG7Silix_fd7af8dzBg8Y8_vY2ai0fqyuGAZuBZZ_X8H3hBuJO_r1Wl9zqVT5E88IM_Niiq1MgqclBBhnl-s8wyKO0coEbxFJYeBnvDawq7o\/s16000\/Reddit%2520profile%2520of%2520u%2520-%2520BroadDepartment573%2520showing%2520the%2520Four%2520Year%2520Club%2520trophy%2520alongside%2520an%2520otherwise%2520empty%2520activity%2520history%2520%28Source%2520-%2520Hexastrike%29.webp?ssl=1\" alt=\"Reddit profile of u - BroadDepartment573 showing the Four Year Club trophy alongside an otherwise empty activity history (Source - Hexastrike)\"><figcaption class=\"wp-element-caption\">Reddit profile of u \u2013 BroadDepartment573 showing the Four Year Club trophy alongside an otherwise empty activity history (Source \u2013 Hexastrike)<\/figcaption><\/figure>\n<\/div>\n<p>Every post follows the same template, claiming the software was reverse engineered with all license checks removed. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiergdET119oL6Ds_hzj4Td6FB37j4l_n57muIWrJHkRFcXpLnizqWrVsQyvpwF69Rp8WQilExk5O6e1F1OHio30w2jQOqZ5ZH4CVCYy6aSMT4q4M4dvOpqw1lltAoFpxFP55CS-dbkqM1nwTMwJqDWd3HYdYNVQEeybWOurd7jZq8Fb7SnBpNSeaygzMU\/s16000\/Post%2520body%2520claiming%2520the%2520software%2520is%2520reverse%2520engineered%2520with%2520all%2520license%2520checks%2520removed%2520and%2520premium%2520access%2520unlocked%2520forever%2520%28Source%2520-%2520Hexastrike%29.webp?ssl=1\" alt=\"Post body claiming the software is reverse engineered with all license checks removed and premium access unlocked forever (Source - Hexastrike)\"><figcaption class=\"wp-element-caption\">Post body claiming the software is reverse engineered with all license checks removed and premium access unlocked forever (Source \u2013 Hexastrike)<\/figcaption><\/figure>\n<\/div>\n<p>Separate download links are offered for Windows, macOS, and macOS 15 \u2014 a level of platform targeting that shows the actor understands Apple\u2019s <a href=\"https:\/\/cybersecuritynews.com\/macos-gatekeeper\/\" id=\"104493\" target=\"_blank\" rel=\"noreferrer noopener\">Gatekeeper restrictions<\/a> in macOS Sequoia. <\/p>\n<h2 class=\"wp-block-heading\" id=\"the-infection-mechanism\"><strong>The Infection Mechanism<\/strong><\/h2>\n<p>Payloads are hosted on compromised legitimate business websites, lending added credibility to the download links. <\/p>\n<p>On Windows, the extracted executable is bloated to over 784 megabytes through null-byte padding in its PE resource section, deliberately sized to exceed antivirus scan limits. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgLEwuw9qVtIt3G0P8d4qfXbAYaOBH_ROaATWmKe4N1WaL1hv1LE1Rl7XDxkr0fggHMGH4j-WgLF0IFOKrB0goeaBKuWdS2XUKiR2ZIdmZOkoX1tGuxYkg5v4LMVYMtE5Jwndc6wnHptDPbgGF4eYOVX1cV9qvjEthYDfdMSOutzxPrChtAFsOmNev6W7g\/s16000\/Entropy%2520graph%2520of%2520the%2520executable%2520showing%2520the%2520resource%2520section%2520filled%2520almost%2520entirely%2520with%2520zero-byte%2520padding%2520%28Source%2520-%2520Hexastrike%29.webp?ssl=1\" alt=\"Entropy graph of the executable showing the resource section filled almost entirely with zero-byte padding (Source - Hexastrike)\"><figcaption class=\"wp-element-caption\">Entropy graph of the executable showing the resource section filled almost entirely with zero-byte padding (Source \u2013 Hexastrike)<\/figcaption><\/figure>\n<\/div>\n<p>Beneath the padding sits a 44-kilobyte self-extracting cabinet that drops a batch script named Receipt.gif. <\/p>\n<p>Despite the image extension, it is a 235-line obfuscated script that reassembles a <a href=\"https:\/\/cybersecuritynews.com\/vidar-stealer-bypassing-browser-security\/\" id=\"130715\" target=\"_blank\" rel=\"noreferrer noopener\">Vidar infostealer<\/a> from split file fragments using character substitution to defeat signature-based detection. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiuLNlZKDIiWF5vkhKu1qBVZTUFov2zOHHt_3sEBnm7BGVRTU4fJzND7_p0ZW7TebKOQMj2Tk-IKLyD0rBxNOTHA2P-GiocZbUTSO5pv0ZHkTfNzAYXtjwFowkHECKyWWqjJB9t2gfXWcwbJIOYcr3FQGHfujFjRT7jaWRilbPLbMcko8dQHEAZAynLGiw\/s16000\/First%2520lines%2520of%2520Receipt.gif%2520showing%2520the%2520Set%2520variable%2520chain%2520with%2520random%2520dictionary%2520words%2520inserted%2520as%2520obfuscation%2520padding%2520%28Source%2520-%2520Hexastrike%29.webp?ssl=1\" alt=\"First lines of Receipt.gif showing the Set variable chain with random dictionary words inserted as obfuscation padding (Source - Hexastrike)\"><figcaption class=\"wp-element-caption\">First lines of Receipt.gif showing the Set variable chain with random dictionary words inserted as obfuscation padding (Source \u2013 Hexastrike)<\/figcaption><\/figure>\n<\/div>\n<p>The archive password \u2014 either \u201cgithub\u201d or \u201ccodeberg\u201d \u2014 is posted directly in the Reddit thread, both names chosen to evoke legitimate developer platforms and lower suspicion.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/c61511c8-5b48-48f5-8821-2f162ef6d6ba\/Hackers-Use-Fake-TradingView-Premium-Posts-on-Reddit-to-Deliver-Vidar-and-AMOS-Stealers.pdf?AWSAccessKeyId=ASIA2F3EMEYEZZ4KAVWO&amp;Signature=7k%2FaPqhNW1rDtXJvT5YO3c3VkNI%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEBYaCXVzLWVhc3QtMSJIMEYCIQDlnR4flq5VG%2FqXubRY43w8fPi420%2BkjRT8bDba5DJ%2B%2BQIhALMHFO1VKhSUgI2U%2BJ%2FCs01b5rKew5abzyYQg2kX%2Bv%2FQKvwECN7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgxttiYdBRhAdUhcAk4q0AQZKQrMXE0rSKjVEREqeJTffq3ZvbMI%2FMgktV0yw9SiZ%2BjWFeGnaTHiFZfcuLTGrXk3Q%2B8VMpmUzzRraQC1GsfUdrUb9sC0mfhANvwTDnwL%2Fp6Ao0ZULCn6iZbE2GgMQSUGgdzGxwWcktUxWOKr%2BjzBPhsIevzqnRxeuOOqLVbcJgJulc8sYaQw2rRjQTT8ZhdoLPjnwLa30biFQHUaC2l30tOj%2B8n5wStIjydCLNA8wcwpDMmLrober%2FUoWyRWuTHTiOwFEoR6irTCQa5bQWn20QTuee7rc9nxXoIchwMiE4qDIful1KkdUTXywm7fa7xdw07NdM7SZE80R9319ecqpX3pxqk%2FmSIovCZS7BeFBZNFADjEUKzlIyGxRk6hCBHbokXBIJA%2ByYqkS9aw24PK%2B9%2Bn0OXe8Kw8jt8COgoNds%2BrGRkLPISDsyLaZwm%2F85lzy%2BjO50JNhX3HW59sogFlMZTCSGAiSoFEjN%2F4vouo0WkhtnopcPIvjnzwg%2FYFu6sEUG%2FjuSVQIIneOXWn64kuNmBmAv2JzVyZjVJkoejUVRaJeorMWuhwNT33UV%2BLBeF6usSvN3pYlLFl3MnV4b%2B2lV139L3LuuvXwM2xakRquzJCm4GCDYcVRNcbUwr8qK%2FPaeVtKZ9zD78NyPvimgjPeXvPM46xcwKdqBs49t4J92b1ZWx23IaDYqgUp8xK7VmNYbczLy%2BwbRHFGWD0r%2BrrQ44Nt6TRPhYetFTIyT%2BSsFouwSqDx1%2FiB5X1wfJDkkwMo0X0fsXZKPr2JX3dmo9kMK%2Bj0s4GOpcBNTLUBpOMTKE4C1radSZ5%2B5mOhGSv7hsA7wSWN7ufzaEp%2FDoFfXDfZxRxRVNqX2QMBitz1XjdOneBBBsAdgx1vVkHnDTRCgHpKuCzgLG6BCvzBdd9VEsmX6QIXbC8sIps7Qm8fOwyvY9%2F3B4lhlkoq0ZPs%2B1XntWwsm2AGJdZCksi6q9f%2BZPY4wSVNrM0mwKcDvgCkpo9GA%3D%3D&amp;Expires=1775541451\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>On macOS, the download is a disk image that mounts with a TradingView-branded background to mimic a real installer. Inside sits a compact 217-kilobyte Mach-O binary that decrypts an <a href=\"https:\/\/cybersecuritynews.com\/amos-macos-stealer-hides-in-github\/\" id=\"111047\" target=\"_blank\" rel=\"noreferrer noopener\">AMOS stealer<\/a> at runtime through a polymorphic XOR loop. <\/p>\n<p>Once executed, AMOS harvests credentials and cookies from Chrome, Firefox, Safari, Brave, Edge, and Opera, copies wallet files from Exodus, Electrum, and MetaMask, and exfiltrates everything over HTTP within seconds. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjn2EBmWA5XRX5GcDMqj4Tr22fjSTI8HXXYgNEgBozu6JKY1vaM1R3kMk4pKKyrB-QFK18lG98GIryWew1XBbzgUkJMIPLgdT3FXzaunTE4Ja7qoQd3YGNip5n1M2yPgbXGaHY80vhb1CFVY1-DhvGuKRcwFypBAZCCUlIN7AxIsqpFlCbIBAQyQhg81Hc\/s16000\/Mounted%2520TradingView%2520DMG%2520showing%2520the%2520application%2520icon%2520over%2520a%2520branded%2520background%2520designed%2520to%2520appear%2520like%2520a%2520legitimate%2520installer%2520%28Source%2520-%2520Hexastrike%29.webp?ssl=1\" alt=\"Mounted TradingView DMG showing the application icon over a branded background designed to appear like a legitimate installer (Source - Hexastrike)\"><figcaption class=\"wp-element-caption\">Mounted TradingView DMG showing the application icon over a branded background designed to appear like a legitimate installer (Source \u2013 Hexastrike)<\/figcaption><\/figure>\n<\/div>\n<p>Organizations should add the identified distribution domains to web proxy and DNS blocklists, and hunt for patterns where Reddit browsing is followed quickly by a large ZIP download from an unrelated domain. <\/p>\n<p>On Windows, flag wextract.exe spawning cmd.exe with delayed variable expansion. On macOS, monitor for unsigned applications calling osascript or making unexpected dscl authonly credential validation attempts. <\/p>\n<p>Anyone with any doubt about exposure should treat it as a confirmed compromise \u2014 browser passwords, session cookies, and <a href=\"https:\/\/cybersecuritynews.com\/crypto-casinos-cybersecurity-protecting-your-wallet\/\" id=\"137197\" target=\"_blank\" rel=\"noreferrer noopener\">crypto wallet<\/a> keys should all be considered stolen. Downloading cracked software remains one of the most reliable ways threat actors find victims today.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-use-fake-tradingview-premium-posts\/\">Hackers Use Fake TradingView Premium Posts on Reddit to Deliver Vidar and AMOS Stealers<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-use-fake-tradingview-premium-posts\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Use Fake TradingView Premium Posts on Reddit to Deliver Vidar and AMOS Stealers A threat actor has been running an active campaign on Reddit, using fake posts that promise free TradingView Premium access to deliver two malware families \u2014 Vidar on Windows and AMOS on macOS. The operation is still live, with new posts [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-11914","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11914"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11914"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11914\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11914"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11914"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11914"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}