{"id":22249,"date":"2025-03-20T12:14:15","date_gmt":"2025-03-20T10:14:15","guid":{"rendered":"https:\/\/forklog.com\/en\/experts-warn-of-malware-infested-tradingview-premium-software\/"},"modified":"2025-03-20T12:14:15","modified_gmt":"2025-03-20T10:14:15","slug":"experts-warn-of-malware-infested-tradingview-premium-software","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/experts-warn-of-malware-infested-tradingview-premium-software\/","title":{"rendered":"Experts Warn of Malware-Infested TradingView Premium Software"},"content":{"rendered":"<p>Malicious actors are promoting a compromised version of TradingView Premium containing malware capable of stealing personal data and users&#8217; crypto assets, according to experts from <a href=\"https:\/\/www.malwarebytes.com\/blog\/scams\/2025\/03\/amos-and-lumma-stealers-actively-spread-to-reddit-usersa\">Malwarebytes<\/a>.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>&#8220;We have heard of victims whose crypto wallets were emptied, after which criminals sent phishing links on their behalf,&#8221; noted the firm&#8217;s senior security researcher, J\u00e9r\u00f4me Segura.<\/em><\/p>\n<\/blockquote>\n<p>According to him, the compromised installation files are distributed through cryptocurrency sections on Reddit, masquerading as a &#8220;free&#8221; cracked version of the official TradingView app for financial charting.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-qw.googleusercontent.com\/docsz\/AD_4nXcN5WAvlqpr1W063uYW-XsHDsrtCwGwEVUdI45IeklT7oeSVaZMpnsOko7_ukI1sood2E0_fQA_BQFTFCVWUzWAnW6yekDVa92WdFLSHiOhgrbUJMlITsg41rtJ0BteWocBrk4qVA?key=3qBRLfuPZtfLgz8Yt48Xmdhe\" alt=\"Experts Warn of Malware-Infested TradingView Premium Software\"\/><figcaption class=\"wp-element-caption\">Screenshot of a Reddit post with links to malware. Source: <a href=\"https:\/\/www.malwarebytes.com\/blog\/scams\/2025\/03\/amos-and-lumma-stealers-actively-spread-to-reddit-usersa\">Malwarebytes<\/a>.\u00a0<\/figcaption><\/figure>\n<p>In their Reddit thread, the perpetrators claimed the software is compatible with Mac and Windows and includes &#8220;all premium features.&#8221; They even offered &#8220;technical support&#8221; to some eager downloaders.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-qw.googleusercontent.com\/docsz\/AD_4nXeqIMqJpgK-x6-V0MMM64Sq_y6EIYFQ_jrMOI5CBCXKzOwFJV4iqL5soJSxXVJz5s4xVGiCqLjfNXylFPWK5bJlE6KoS-ZxnPdirV4yNYymEnDO8-A47BHLcgoAATETE4CQvwom4Q?key=3qBRLfuPZtfLgz8Yt48Xmdhe\" alt=\"Experts Warn of Malware-Infested TradingView Premium Software\"\/><figcaption class=\"wp-element-caption\">Source: <a href=\"https:\/\/www.malwarebytes.com\/blog\/scams\/2025\/03\/amos-and-lumma-stealers-actively-spread-to-reddit-usersa\">Malwarebytes<\/a>.<\/figcaption><\/figure>\n<p>In one instance, a supposed hacker advised a user to ignore MacOS warnings as &#8220;Apple&#8217;s excessive caution&#8221; and a reaction to the cracked version of the app lacking proper digital signatures.\u00a0<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>&#8220;Don&#8217;t worry, a real virus on Mac is a rarity, I&#8217;ve never seen them slip through like this,&#8221; they assured a trader on Reddit.\u00a0<\/em><\/p>\n<\/blockquote>\n<p>According to Malwarebytes, the files offered by the perpetrators contained the Lumma Stealer and Atomic Stealer viruses. The former is an infostealer targeting crypto wallets and two-factor authentication data in browser applications. The latter, known since 2023, is a thief of passwords stored in the OS.\u00a0<\/p>\n<p>The installation packages were hosted on a server of a cleaning company in Dubai, while the control server was &#8220;registered by someone from Russia.&#8221;<\/p>\n<p>Experts noted that such &#8220;free&#8221; versions of licensed software often come with malicious files and advised caution when considering such offers.<\/p>\n<p>Back in March, researchers from Microsoft Incident Response <a href=\"https:\/\/forklog.com\/en\/news\/microsoft-warns-of-trojan-targeting-cryptocurrency-wallets\">discovered<\/a> a new remote access trojan, StilachiRAT, aimed at stealing cryptocurrencies and user credentials.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malicious actors are promoting a compromised version of TradingView Premium containing malware capable of stealing personal data and users&#8217; crypto assets, according to experts from Malwarebytes. &#8220;We have heard of victims whose crypto wallets were emptied, after which criminals sent phishing links on their behalf,&#8221; noted the firm&#8217;s senior security researcher, J\u00e9r\u00f4me Segura. According to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":22248,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[44,1400,1781],"class_list":["post-22249","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybercrime","tag-reddit","tag-tradingview"],"aioseo_notices":[],"amp_enabled":true,"views":"96","promo_type":"","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/22249","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=22249"}],"version-history":[{"count":0,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/22249\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/22248"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=22249"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=22249"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=22249"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}