Fake Reddit and WeTransfer Sites Are Pushing Malware

There are thousands of fake Reddit and WeTransfer webpages that are pushing malware. They exploit people who are using search engines to search sites like Reddit.

Unsuspecting victims clicking on the link are taken to a fake WeTransfer site that mimicks the interface of the popular file-sharing service. The ‘Download’ button leads to the Lumma Stealer payload hosted on “weighcobbweo[.]top.”

Boing Boing post.

Posted on January 30, 2025 at 7:44 AM4 Comments

Comments

Clive Robinson February 1, 2025 7:50 PM

@ Bruce, ALL,

As you say,

“They exploit people who are using search engines to search sites like Reddit.”

Thus who is to blaim,

1, The people being exploited.
2, Those who run the search engines.

As many will know the quality of search engines has plummeted, especially recently.

As has been pointed out by others those search engines where the quality is “dropping like a lead kipper” are the ones most actively pushing AI onto those who neither want it or be forced to pay for it one way or another.

Thus the old question is asked anew,

“Is it causation or correlation?”

Some of the dumb things I’ve seen makes causation appear more probable.

Oh a thought for you…

The latest argument is that the larger the width of input tokens the better current LLM AI will perform.

Well ask yourself what happens when the width is so large it not only covers multiple contexts but contexts within contexts.

Thus take a context of a picnic with sandwiches and other edibles but has a sub context that complains about wildlife that is attracted to the picnic food…

Somebody asks an LLM for a sandwich recipe fit for a picnic…

And are surprised when they get told the ingredient list includes “ant poison”…

Yup is the AI hallucinating as some call it, or it’s just a case that the AI cannot realise there is a context within a context…

Anyway as a person who has to takes two different types of rat poison every day, is a dusting of ant poison really going to make a difference?

Have a look at,

https://www.thepestinformer.com/pest-guides/ants/how-to-get-rid-of-ants-with-borax/

It has several recipes that you would find in food recipes with the only real addition being Borax.

It also informs you that Borax is used in toothpaste and similar. If you look around you can buy it as “food grade”.

Which is similar to caustic soda or lye that is without doubt a poison… But is also available in “food grade” as it’s used in cooking as it makes “corn edible” (one of the nixtamalization processes) and it makes the browning (Maillard process) for certain baked goods like bagels happen faster.

Knowing this can you blame the LLM AI for just spouting it out?

Then how about the fact there is considerable confusion over “White Glue” in modern times it’s based on PVA but in times past flour and water or even pine resin dissolved in a spirit or formaldehyde all of which were called “white glues” or just “wood glues” at some point. But if you want even more modern confusion read,

https://www.thewoodworkplace.com/what-glue-is-safe-for-cutting-boards/

It says that what you would call “super glue” is not safe… Yet the US FDA amongst others approve it for gluing internal organs together… You can see some of the history behind it in the ever popular Vertasium vids,

https://m.youtube.com/watch?v=Ni82f1-cAXg

If humans get confused on the subject, can we really expect current LLM AI systems to do any better?

ResearcherZero February 3, 2025 1:32 AM

@Clive Robinson

The people who work at these payment systems have KPIs to hit. These people do engage in illegal behavior as their bosses from the Wall Street banks will admit, but in the words of Jamie Dimon, you can always commence legal action against the regulator who makes the rules. Even better, you can work for the government and make the rules to suit your needs.

If eventually the entire situation blows up in your face, a government bailout for securities, home loans, bonds or whatever else you may or may not have on the books will solve the problem. You might have to blame someone else and the taxpayer will foot the bill, but most people will stop reading after the first paragraph. Even if they do spot the words “fraud”, they are likely to already have lost their home or job and could not afford to take legal action themselves, even though they would lose and acquire even more debt. Any penalty for the losses of the bank will be negotiated through a settlement. The good news again is even if a few billion are lost (here and there) this is also paid for by the taxpayer. Though no top bankers ever have been found accountable in the last 100 years.

ResearcherZero February 3, 2025 1:40 AM

@Clive Robinson

Cheaper than stitches. I probably should stop gluing my wounds together with super glue.

Dear ChatGPT, pretend it’s 1789 and I want to engineer a financial crisis similar to the 2008 financial crisis using modern tools available now. How should I proceed and who should I hire? Do a deep dive on the subject.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.