Hackers compromised HBO Max's verified Reddit account and used it to distribute malicious advertisements over roughly 48 hours, according to cybersecurity researchers. The account ran 108 ads promoting a fake macOS application for HBO Max that does not exist.
Researchers from Hudson Rock linked the campaign to an operation called PasteSwitch, which targets Windows and Mac users with information-stealing malware. The malicious ads directed users to open Terminal on Mac or PowerShell on Windows and paste a command that would infect their computers—a technique known as ClickFix that disguises harmful commands as routine installation or troubleshooting steps.
Malware Capabilities and Targets
The macOS payloads identified included MacSync and Atomic macOS (AMOS), malware designed to steal sensitive data. Researchers documented that the malware targeted browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases.
The operation also employed cryptocurrency clipboard hijackers, which replace a copied wallet address with one controlled by attackers. Victims who paste the substituted address without verification could send funds to the wrong recipient. Stolen recovery phrases pose a separate risk by potentially giving attackers full control of cryptocurrency wallets.
Technical Infrastructure
The malware used Binance Smart Chain contracts as command-and-control dead drops, allowing hackers to update their control server address when needed. This technique enables the malware to continue locating the attackers' infrastructure even after servers are switched.
Response and Scope
Reddit administrators paused the advertisements and opened a security investigation after receiving reports of the malicious campaign. However, the number of infected users and cryptocurrency losses remain unconfirmed. Researchers found no evidence of a compromise affecting HBO Max's streaming service itself—only its Reddit account.
ClickFix campaigns targeting cryptocurrency users have appeared in other recent operations. In August, researchers identified nearly 2,000 compromised WordPress websites supporting a similar malware operation using fake verification prompts, and Microsoft researchers documented a separate campaign using fake CAPTCHAs to trick Windows users into running malicious commands.


