Threat Actors Compromise HBO Max Reddit Account to Promote Malware
Key Takeaways A verified HBO Max Reddit account was compromised to distribute malware through fraudulent ads. The campaign, dubbed “PasteSwitch” and “ClickFix,” lured users...
Key Takeaways
- A verified HBO Max Reddit account was compromised to distribute malware through fraudulent ads.
- The campaign, dubbed “PasteSwitch” and “ClickFix,” lured users with fake software, including a non-existent macOS HBO Max app.
- Victims were tricked into executing malicious commands via Terminal, leading to the potential installation of credential stealers, cryptocurrency clippers, and other malware.
- The attack leveraged social engineering and brand impersonation rather than software vulnerabilities, demonstrating the ongoing threat of malvertising.
Hackers Exploit Verified Reddit Account in Sophisticated Malware Campaign
In a concerning development for online security, threat actors successfully hijacked a verified Reddit account belonging to HBO Max, u/hbomax, to disseminate malware. Over a 48-hour period, the compromised account published 108 malicious “ClickFix” advertisements, redirecting unsuspecting users to deceptive web pages promoting fake software.
Table Of Content
This attack did not exploit a software vulnerability, but rather relied on a sophisticated social engineering approach. The attackers crafted a convincing landing page that mimicked official HBO Max branding, offering a purported native HBO Max application for macOS. Crucially, instead of providing a direct download, the page instructed visitors to copy and paste a command directly into their system’s Terminal, thereby tricking users into manually executing attacker-controlled code.
PasteSwitch: A Multi-Platform Malvertising Operation
Researchers at HudsonRock, collaborating with independent cybersecurity expert Kirk from ADAMnetworks, have identified this activity as part of a broader, cross-platform malicious operation they’ve named PasteSwitch. HudsonRock said in a report that PasteSwitch extends beyond fake streaming apps, encompassing lures for AI tools, developer utilities, and disk-cleaning software. The potential ramifications of this operation are extensive.
The report, also detailed in a detailed analysis, indicates that PasteSwitch is capable of deploying a range of malicious payloads, including credential stealers, Windows loaders, and cryptocurrency-address clippers. This poses significant risks to browser data, saved passwords, and digital assets.
The operation’s adaptability is a key concern. It employs a reusable framework that allows attackers to easily swap out brands, lures, and payloads while maintaining consistent underlying delivery mechanisms. Reddit has since paused the malicious ads and launched an investigation. This incident serves as a stark reminder that a verified account does not inherently guarantee the safety of associated downloads or promotions.
The HBO Max Incident: A Case Study in Deception
The suspicious advertising came to light after a Reddit user encountered what appeared to be an official ad from u/hbomax. The ad promoted a macOS application for HBO Max, despite no such standalone app officially existing. The linked landing page meticulously replicated HBO Max branding, creating a compelling illusion before presenting its malicious trap.
The “ClickFix” method bypasses traditional software installation by prompting users for a manual action. Upon clicking “Download,” an overlay appeared, instructing the user to copy and paste a command into their Terminal. This technique, demonstrated in other recent ClickFix malware attacks, effectively manipulates users into executing attacker-supplied code on their systems.
The threat actors exhibited agility in their campaign, rapidly cycling through domains as they were detected and blocked. The ads included 40 streaming-themed placements using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-desktop[.]com, and six for hbomax-macos[.]com. The compromised HBO Max account provided a trusted advertising platform for two days, leveraging brand reputation to lower user vigilance.
PasteSwitch’s Expanding Reach Across Platforms
The researchers uncovered a dynamic delivery system that adapts to the visitor’s operating system and the specific campaign. For macOS users, the pasted command could fetch MacSync, AMOS-related helpers, or fake cryptocurrency wallet applications. These payloads are designed to harvest credentials, Telegram data, Apple Notes, and macOS passwords, with fake wallets specifically targeting recovery phrases.
Windows users were directed through a separate “InstallFix” route, utilizing mshta and PowerShell. This involved a disguised MP3/HTA file that could establish a scheduled task, launch 32-bit PowerShell, and disable the Antimalware Scan Interface before executing further malicious code. The “Amatera” payload could then load directly into memory, evading file-based security checks. Furthermore, the report documented deceptive TLS traffic, where connections to attacker-controlled IPs presented “facebook.com” as the visible server name, potentially misleading basic network logs.
An additional threat vector of the operation is its “clipper” branch. “AnimateClipper” and “ZigClipper” monitor the victim’s clipboard, automatically replacing copied cryptocurrency addresses with an attacker’s address. These clipper modules can retrieve current command-and-control domains from Binance Smart Chain contracts, enabling the actors to frequently rotate their infrastructure and maintain persistence.
What You Should Do
- Exercise Extreme Caution with Copy-Paste Commands: Never copy and paste commands from advertisements, pop-ups, or websites into your Terminal or command prompt, especially if prompted by an unexpected download. Always validate software through official vendor channels.
- Verify Software Sources: Download applications only from official app stores (e.g., Apple App Store, Microsoft Store) or directly from the legitimate vendor’s website. Be wary of third-party download sites or ads promoting “native” versions of software that may not exist.
- Monitor for Unusual Activity: Defenders should block all listed Indicators of Compromise (IoCs). Investigate any alerts related to unexpected Terminal, Run-dialog,
mshta, or PowerShell activity. - Review and Reset Credentials: If you suspect exposure, immediately reset passwords for affected accounts and enable multi-factor authentication (MFA) wherever possible. Monitor for unusual browser data collection.
- Enhance Network Monitoring: Network teams should correlate direct IP connections with suspicious SNI (Server Name Indication), DNS, and certificate behavior. Pay close attention to blockchain-based command-and-control channels in investigations.
- Educate Users: Regularly remind staff and users about the dangers of malvertising, social engineering tactics, and the importance of verifying software sources.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.