Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Hackers Used Hijacked HBO Max Reddit Account to Distribute Crypto-Stealing Malware

Cybercriminals compromised HBO Max's verified Reddit account to run 108 malicious advertisements promoting fake applications designed to steal cryptocurrency wallet data and login credentials over a 48-hour period.
58 minutes ago 6 views
Hackers Used Hijacked HBO Max Reddit Account to Distribute Crypto-Stealing Malware

Hackers compromised HBO Max's verified Reddit account and used it to distribute malicious advertisements over roughly 48 hours, according to cybersecurity researchers. The account ran 108 ads promoting a fake macOS application for HBO Max that does not exist.

Researchers from Hudson Rock linked the campaign to an operation called PasteSwitch, which targets Windows and Mac users with information-stealing malware. The malicious ads directed users to open Terminal on Mac or PowerShell on Windows and paste a command that would infect their computers—a technique known as ClickFix that disguises harmful commands as routine installation or troubleshooting steps.

Malware Capabilities and Targets

The macOS payloads identified included MacSync and Atomic macOS (AMOS), malware designed to steal sensitive data. Researchers documented that the malware targeted browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases.

The operation also employed cryptocurrency clipboard hijackers, which replace a copied wallet address with one controlled by attackers. Victims who paste the substituted address without verification could send funds to the wrong recipient. Stolen recovery phrases pose a separate risk by potentially giving attackers full control of cryptocurrency wallets.

Technical Infrastructure

The malware used Binance Smart Chain contracts as command-and-control dead drops, allowing hackers to update their control server address when needed. This technique enables the malware to continue locating the attackers' infrastructure even after servers are switched.

Response and Scope

Reddit administrators paused the advertisements and opened a security investigation after receiving reports of the malicious campaign. However, the number of infected users and cryptocurrency losses remain unconfirmed. Researchers found no evidence of a compromise affecting HBO Max's streaming service itself—only its Reddit account.

ClickFix campaigns targeting cryptocurrency users have appeared in other recent operations. In August, researchers identified nearly 2,000 compromised WordPress websites supporting a similar malware operation using fake verification prompts, and Microsoft researchers documented a separate campaign using fake CAPTCHAs to trick Windows users into running malicious commands.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.