{"id":1655,"date":"2025-01-31T05:14:40","date_gmt":"2025-01-31T05:14:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/01\/31\/fake-reddit-and-wetransfer-sites-are-pushing-malware-html\/"},"modified":"2025-01-31T05:14:40","modified_gmt":"2025-01-31T05:14:40","slug":"fake-reddit-and-wetransfer-sites-are-pushing-malware-html","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/01\/31\/fake-reddit-and-wetransfer-sites-are-pushing-malware-html\/","title":{"rendered":"Fake Reddit and WeTransfer Sites are Pushing Malware"},"content":{"rendered":"\n<div>Fake Reddit and WeTransfer Sites are Pushing Malware<\/div>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>There are thousands of <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hundreds-of-fake-reddit-sites-push-lumma-stealer-malware\/\">fake<\/a> Reddit and WeTransfer webpages that are pushing malware. They exploit people who are using search engines to search sites like Reddit.<\/p>\n<blockquote>\n<p>Unsuspecting victims clicking on the link are taken to a fake WeTransfer site that mimicks the interface of the popular file-sharing service. The \u2018Download\u2019 button leads to the <a href=\"https:\/\/app.any.run\/tasks\/a629e4b1-433b-427e-8040-79d4aa13c245\">Lumma Stealer payload<\/a> hosted on \u201cweighcobbweo[.]top.\u201d<\/p>\n<\/blockquote>\n<p>Boingboing <a href=\"https:\/\/boingboing.net\/2025\/01\/28\/fake-reddit-pages-are-serving-up-malware.html\">post<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Bruce Schneier<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/www.schneier.com\/blog\/archives\/2025\/01\/fake-reddit-and-wetransfer-sites-are-pushing-malware.html\">Go to bruce schneier<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fake Reddit and WeTransfer Sites are Pushing Malware There are thousands of fake Reddit and WeTransfer webpages that are pushing malware. They exploit people who are using search engines to search sites like Reddit. Unsuspecting victims clicking on the link are taken to a fake WeTransfer site that mimicks the interface of the popular file-sharing [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[57,258,1],"tags":[87],"class_list":["post-1655","post","type-post","status-publish","format-standard","hentry","category-bruce-schneier","category-malware","category-uncategorized","tag-bruce-schneier"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1655"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=1655"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1655\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=1655"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=1655"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=1655"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}