HBO Max Reddit account used to spread 108 malware and crypto stealing ads in 48 hours

Photo: Pixabay / Pexels

HBO Max Reddit account used to spread 108 malware and crypto stealing ads in 48 hours

A compromised HBO Max Reddit account pushed 108 malicious ads linked to malware targeting Mac and Windows users.

A compromised verified HBO Max Reddit account was used to distribute 108 malicious ads over a 48 hour period as part of a broader malware campaign researchers have dubbed PasteSwitch.

The campaign was uncovered after a Reddit user spotted an advertisement from the official u/hbomax account promoting a native HBO Max application for macOS, despite no such standalone app existing.

Users who followed the ad were directed to a fake HBO Max website. Clicking the download button displayed a ClickFix prompt instructing users to copy and paste a command into their terminal rather than downloading an application normally.

Advertisement

Researchers from Hudson Rock and ADAMnetworks linked the incident to PasteSwitch, a larger operation targeting both macOS and Windows users through fake software downloads and other deceptive ads.

The compromised HBO Max account published 108 ads across several domains during the campaign. Forty promoted a fake HBO Max service, while others impersonated AI tools, developer software and macOS utilities.

On macOS, PasteSwitch distributed malware capable of stealing browser credentials, Telegram data, Apple Notes and passwords. Researchers also found fake Ledger, Trezor Suite and Exodus applications designed to steal crypto wallet recovery phrases.

Windows users were served a separate infection chain involving PowerShell and the Amatera Stealer, which researchers said could load malware directly into memory and disguise malicious network traffic as connections to Facebook.

The operation also deployed crypto clipboard malware designed to replace wallet addresses when victims copied or pasted them. Researchers said some variants used Binance Smart Chain contracts to distribute updated command and control domains, making the infrastructure easier to rotate when domains were blocked.

Reddit later paused the affected advertisements and opened an investigation with its Security and Safety teams to secure the compromised account.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
HBO Max Reddit account used to spread 108 malware and crypto stealing ads in 48 hours
HBO Max Reddit account used to spread 108 malware and crypto stealing ads in 48 hours

A compromised HBO Max Reddit account pushed 108 malicious ads linked to malware targeting Mac and Windows users.

Share

Add us on Google

Photo: Pixabay / Pexels

A compromised verified HBO Max Reddit account was used to distribute 108 malicious ads over a 48 hour period as part of a broader malware campaign researchers have dubbed PasteSwitch.

The campaign was uncovered after a Reddit user spotted an advertisement from the official u/hbomax account promoting a native HBO Max application for macOS, despite no such standalone app existing.

Users who followed the ad were directed to a fake HBO Max website. Clicking the download button displayed a ClickFix prompt instructing users to copy and paste a command into their terminal rather than downloading an application normally.

Advertisement

Researchers from Hudson Rock and ADAMnetworks linked the incident to PasteSwitch, a larger operation targeting both macOS and Windows users through fake software downloads and other deceptive ads.

The compromised HBO Max account published 108 ads across several domains during the campaign. Forty promoted a fake HBO Max service, while others impersonated AI tools, developer software and macOS utilities.

On macOS, PasteSwitch distributed malware capable of stealing browser credentials, Telegram data, Apple Notes and passwords. Researchers also found fake Ledger, Trezor Suite and Exodus applications designed to steal crypto wallet recovery phrases.

Windows users were served a separate infection chain involving PowerShell and the Amatera Stealer, which researchers said could load malware directly into memory and disguise malicious network traffic as connections to Facebook.

The operation also deployed crypto clipboard malware designed to replace wallet addresses when victims copied or pasted them. Researchers said some variants used Binance Smart Chain contracts to distribute updated command and control domains, making the infrastructure easier to rotate when domains were blocked.

Reddit later paused the affected advertisements and opened an investigation with its Security and Safety teams to secure the compromised account.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.