{"id":18306,"date":"2025-03-20T16:32:15","date_gmt":"2025-03-20T16:32:15","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=18306"},"modified":"2025-03-20T16:32:15","modified_gmt":"2025-03-20T16:32:15","slug":"crypto-traders-beware-this-fake-tradingview-is-stealing-funds","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=18306","title":{"rendered":"Crypto Traders Beware: This Fake TradingView Is Stealing Funds"},"content":{"rendered":"<div>\n<p>A new threat is emerging from hackers who are disseminating <a href=\"https:\/\/www.malwarebytes.com\/blog\/scams\/2025\/03\/amos-and-lumma-stealers-actively-spread-to-reddit-users\" target=\"_blank\" rel=\"noopener nofollow\">hazardous software to Reddit<\/a> users who are seeking free trading tools. Malwarebytes, a cybersecurity firm, has reported that scammers have installed malware in phony \u201ccracked\u201d versions of TradingView Premium. This malware has the potential to pilfer personal information and empty crypto wallets. Malwarebytes Senior security researcher Jerome Segura issued the warning in a blog post on March 18.<\/p>\n<h2>Victims Lose Crypto, Their Identity Gets Stolen<\/h2>\n<p>Segura reported that victims had their <a href=\"https:\/\/www.bitdegree.org\/crypto\/news\/cracked-tradingview-premium-spreads-malware-steals-crypto-wallets\" target=\"_blank\" rel=\"noopener nofollow\">crypto wallets depleted<\/a> and later impersonated by criminals who sent phishing links to their contacts. The attack employs a dual threat, in which two distinct malware programs, Lumma Stealer and Atomic Stealer, collaborate to infiltrate the computers of victims.<\/p>\n<p>Atomic, which began operating in April 2023, targets administrator and keychain credentials, while Lumma has been operational since 2022 and concentrates on cryptocurrency wallets and two-factor authentication browser extensions.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">AMOS and Lumma info stealers have recently been distributed via Reddit posts targeting Mac and Windows users in the crypto space, draining their wallets and stealing personal data. One of the common lures is a cracked version of the popular trading platform TradingView.<\/p>\n<p>A <img decoding=\"async\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/15.0.3\/72x72\/1f9f5.png\" alt=\"\ud83e\uddf5\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"> <a href=\"https:\/\/t.co\/nRweAYv74x\" rel=\"nofollow\" target=\"_blank\">pic.twitter.com\/nRweAYv74x<\/a><\/p>\n<p>\u2014 Malwarebytes (@Malwarebytes) <a href=\"https:\/\/twitter.com\/Malwarebytes\/status\/1902441303067033800?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">March 19, 2025<\/a><\/p>\n<\/blockquote>\n<h2>Scammers Act Helpful While Spreading Malware<\/h2>\n<p>The manner in which the perpetrators interact with potential victims is what distinguishes this scam. The fraudsters are present on cryptocurrency <a href=\"https:\/\/www.brandwatch.com\/social-media-glossary\/subreddit\/#:~:text=Subreddits%20are%20the%20heart%20of,that%20community%20in%20your%20feed.\" target=\"_blank\" rel=\"noopener nofollow\">subreddits<\/a>, where they post links to what they claim are free \u201ccracked\u201d versions of premium financial graphing software for both Windows and Mac.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full\" src=\"https:\/\/www.tradingview.com\/x\/Dg59dj2C\/\" width=\"2315\" height=\"1087\"><\/p>\n<p>Segura observed in the blog post that the original poster\u2019s involvement in the thread is intriguing, as they are \u201chelpful\u201d to users who are asking inquiries or reporting an issue. This additional effort to appear legitimate is instrumental in persuading a greater number of individuals to obtain the hazardous files.<\/p>\n<p>Warning Signs Point To Malicious Software<\/p>\n<p>The infected files exhibit distinct warning signs that users should be aware of, according to Malwarebytes\u2019 analysis. Legitimate software does not employ the distribution method of double-zipped files with password protection, which is the case with the <a href=\"https:\/\/www.cisco.com\/site\/us\/en\/learn\/topics\/security\/what-is-malware.html\" target=\"_blank\" rel=\"noopener nofollow\">malware.<\/a><\/p>\n<p><img loading=\"lazy\" data-recalc-dims=\"1\" decoding=\"async\" class=\"aligncenter size-full wp-image-426638\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/03\/a_d772e5.png?resize=962%2C617\" alt=\"\" width=\"962\" height=\"617\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/03\/a_d772e5.png?w=962 962w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/03\/a_d772e5.png?w=640 640w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/03\/a_d772e5.png?w=768 768w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/03\/a_d772e5.png?w=750 750w\" sizes=\"auto, (max-width: 962px) 100vw, 962px\"><\/p>\n<p>Another significant red flag is that the scammers frequently request that users disable their security software in order to execute the program. The poster\u2019s helpful comments obscure the disclaimer that users download at their own risk, despite the fact that the post acknowledges this.<\/p>\n<p>Crypto Crime Becomes More Professional<\/p>\n<p>Meanwhile, the attack\u2019s trail leads to unexpected locations. Malwarebytes discovered that the malware was hosted on a website owned by a cleaning company in Dubai, while the command and control server was registered in Russia approximately one week ago.<\/p>\n<p>Chainalysis\u2019s 2025 Crypto Crime Report describes a broader pattern in which crypto crime has \u201centered a professionalized era dominated by AI-driven schemes, stablecoin laundering, and efficient cyber syndicates.\u201d This scam is part of this pattern. The report disclosed that illicit cryptocurrency transactions reached over $50 billion in the previous year.<\/p>\n<p><em>Featured image from Gemini Imagen, chart from TradingView<\/em><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A new threat is emerging from hackers who are disseminating hazardous software to Reddit users who are seeking free trading tools. Malwarebytes, a cybersecurity firm, has reported that scammers have installed malware in phony \u201ccracked\u201d versions of TradingView Premium. This malware has the potential to pilfer personal information and empty crypto wallets. Malwarebytes Senior security [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-18306","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/18306","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=18306"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/18306\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=18306"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=18306"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=18306"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}