“TradingView Premium Cracked” Malware Targets Crypto Wallets on Windows and Mac

“TradingView Premium Cracked” Malware Targets Crypto Wallets on Windows and Mac

N
News Editor 01
2026-07-06 19:57:15
Malwarebytes warns of malware disguised as a cracked TradingView Premium, spreading via Reddit to steal crypto wallets. Malware includes Lumma and Atomic Stealer, targeting Windows and Mac, causing millions in losses.

加密货币投资者注意!安全公司Malwarebytes近日发出警告,一种伪装成“TradingView Premium 破解版”的恶意软件正在Reddit上疯狂传播,专门窃取Windows和Mac系统上的加密货币钱包。攻击者声称提供能够解锁付费功能的破解软件,诱骗用户下载安装,实则植入窃密木马。

双重恶意软件:Lumma与Atomic联手

据Malwarebytes分析,该破解文件中包含了两种知名恶意程序——LummaAtomic。Lumma最早出现于2022年,专门针对加密货币钱包,可窃取双因素认证信息;而Atomic(亦称AMOS)则是2023年被发现的恶意软件包,以窃取管理员密码和凭证而臭名昭著。两个恶意软件协同工作,能全面盗取用户数字货币资产。

传播手法:双层压缩与沙箱逃逸

攻击者将恶意文件进行双重ZIP压缩,第二个压缩包设有密码。安全专家指出,这种手法是典型的规避自动扫描检测的方式,正常软件无需如此。安装程序会首先检查是否运行在沙箱环境中,以此躲避安全研究人员的分析。一旦检测通过,AMOS恶意软件便会通过POST请求将窃取的数据发送至位于塞舌尔的服务器(IP: 45.140.13.x)。

利用旧版网站托管,域名来自俄罗斯

Malwarebytes发现,恶意文件托管在一家迪拜清洁公司的网站上,该网站仍在运行PHP 7.3.33版本,该版本自2021年12月起便存在安全漏洞,攻击者正是利用此漏洞控制了网站。而Windows版本所使用的命令与控制(C2)服务器域名为cousidporke.icu,仅在一周前于俄罗斯注册。

Reddit成为“钓鱼”温床

攻击者在Reddit上发布破解链接,并主动提供安装帮助,让受害者感到“安全可靠”。这种持续的技术支持降低了用户的警惕性,使恶意软件得以大规模传播。由于加密货币钱包价值极高,攻击者甚至可能盗取数百万美元的资产。

安全建议:远离破解软件,警惕异常操作

投资者应避免下载任何声称“破解版”的软件,尤其是来自非官方渠道的压缩包。同时,建议启用硬件钱包、定期更新操作系统和杀毒软件,并注意检查网站是否使用过时的PHP版本。如果发现Reddit上出现类似“TradingView Premium Cracked”的帖子,请立即举报。

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.