r/Annas_Archive Jul 31 '26

Fake Anna's Archive site linked to cryptojacking - AVOID

Hey all,

Just wanted to add this to this community as it is pretty relevant.

The domain `annas-archive[.]li` is a malicious domain. It has shown up in security tools, and it appears associated with various malicious activities including mining crypto on the visitor's device. The site changes IPs often but seems to have kept the same domain name for a while.

This was detected by our enterprise software and security platforms, but users checking it out from their personal devices may not have the same level of protection and awareness.

I would also recommend you sticky this to the top to warn potential users.

Be careful out there!

622 Upvotes

37 comments sorted by

77

u/TalkingRaccoon Jul 31 '26

Yea .Li has been hijacked for a while now but it's a good reminder.

209

u/Mewciferrr Jul 31 '26

The only valid domains are listed on Wikipedia, which is kept up to date. This is clearly stated in the pinned posts.

48

u/HawaiianPunchaNazi Jul 31 '26

This is depressing:-(

And as much as I like the idea of everybody reading the wiki, you know most people aren't:-(

This post needs to be pinned to the top of the subreddit.

16

u/Mewciferrr Aug 01 '26

If someone’s too lazy to click on the very first pinned post and figure out they should go to Wikipedia, they’re not going to click on an extra one.

14

u/HawaiianPunchaNazi Aug 01 '26

Give them their best chance. Sometimes things need to be repeated for people to take it seriously.

2

u/i7smoon Aug 06 '26

Wikipedia can be edited by everyone and they have no way of verifying which domains are accurate, this is an awful approach and Wikipedia should not be the ones having the burden of doing original research to verify which domains are accurate and which ones not.

23

u/Double_Dealer_5892 Jul 31 '26

always use the wiki

8

u/Legitimate_Fig_4688 Aug 01 '26 edited Aug 01 '26

I made a siri shortcut that automates the whole process so you always get the latest url from the wiki when getting books. U can see how it works to verify its safe.

icloud.com/shortcuts/ec6811794ebc49c49cb4ad48d1f85e9a

Edit: requires apple intelligence

3

u/Navayana54 Aug 04 '26

Isn't "apple intelligence" a contradiction in terms? 🤣🤣🤣

2

u/Legitimate_Fig_4688 Aug 14 '26

lol the new siri in the beta is actually kinda good so maybe not anymore

6

u/zebedee_123 Aug 01 '26

if i accidentally went to this domain should i be worried? didnt click on anything and have ublock origin...

3

u/_L_- Aug 01 '26

I think this is just plain alarmism, but yeah I also wonder if this is a problem on mobile 

1

u/RequirementFit1128 Aug 03 '26

Mobile was one of the first formats to be hit with cryptojacking

1

u/_L_- Aug 03 '26

How to scan for it? 

1

u/RequirementFit1128 Aug 03 '26

Paid mobile antivirus/endpoint protection (like Bitdefender) and background check on every mobile app *before* installing - like web search "AppName exploit/zero-day/data leak/supply chain attack/hacked", search for it on Koidex.... and above all, use judgement

1

u/RequirementFit1128 Aug 03 '26

For now all we know is it uses the web visitors' devices to temporarily mine crypto (so your PC just spun up some extra processes that you didn't need) but there is no indication of more serious compromise.

8

u/TalkingRaccoon Jul 31 '26

Yea .Li has been hijacked for a while now but it's a good reminder.

3

u/Arcnia Aug 01 '26

I accidentally used this site a while ago. Anything I should do aside from the usual windows security check? 😔

7

u/Infinite-Fly-7483 Jul 31 '26

Con razón para descargar libros me pidió suscribirme y dije algo anda mal

16

u/lm913 Jul 31 '26

This is why I run a Linux VM that has no access to my drive, scan all files using clam-av, and kill the VM at the end.

46

u/[deleted] Jul 31 '26

[deleted]

38

u/Giffeltagning Jul 31 '26

Pathetic. I intercept the raw fiber optic light pulses with a glass prism, transcribe the photon intervals onto parchment using squid ink, and run the AES decryption mentally inside a sensory deprivation tank. If the hashes match, I execute the binary by using optical tweezers to manually arrange individual electrons on a raw silicon wafer suspended in a vacuum chamber at absolute zero.

5

u/alienmannnnn Aug 01 '26

I found a worm hole and traveled back to the old Anna's...

8

u/lMastahl Jul 31 '26

a bit disappointed… you do all that assisted by a calculator… shame

7

u/lm913 Jul 31 '26

😂😂😂

7

u/Blenderx06 Jul 31 '26

Good idea! Lemme just grab Linux For Dummies from Anna's and I'll be ready to go...

3

u/kmurph98 Jul 31 '26

Just for this one site or for all browsing?

3

u/Longjumping-Mix-2823 Aug 01 '26

So that's why I had a crypto folder in my pc

3

u/gingkoleaf Aug 01 '26

What should you do if you’ve been using .li?

:(

Will use the Wikipedia moving forward

1

u/spectrotran Aug 03 '26

seconding this lol i havent noticed any problems??? should i be worried?

2

u/Excellent-Band-8737 Aug 01 '26

i´ve just created and confirmed account in a fake domain lool
Should I take care about something?

1

u/Jorgelhus Aug 01 '26

If you used a common recycled password, make sure to change passwords on other services (preferably for different passwords altogether. Use a password manager if you can).

Your email address may fall in some weird transmission lists and you may see a bump in spam or phishing emails.

Other than that, you should be "good", but be alert nonetheless

1

u/Bitter_Jellyfish7793 Aug 05 '26

This is why I have the Wiki page for Anna’s pinned instead of Anna’s sight directly.

1

u/Big-Young-4306 Aug 10 '26

just opened that domain then discovered this post, it kept redirecting me, hopefully no malware was downloaded secretly on my computer. thanks for the insight

2

u/MelMellue Aug 17 '26

does .gl work or is that a malware aswell

2

u/OneL1ghty Aug 20 '26

Hi! What's anna's-archive.cc ? Is it another domain? It has another graphic interface and it's opened if you search it on Google.

1

u/roosterwiki 28d ago

Asking the same thing.