HBO Max Reddit hack fuels ClickFix malware campaign

Attackers hijacked HBO Max’s verified Reddit advertising account and used it to push 108 malicious ads over roughly 48 hours, turning a trusted brand profile into a high-volume malvertising node targeting Windows and macOS users.[1][2][9][12] Researchers at Hudson Rock and ADAMnetworks say the incident is part of a broader ClickFix operation they call PasteSwitch, which weaponizes fake HBO Max promotions, AI tools and developer utilities to distribute information-stealing malware.[3][8][9] Reddit has since paused the malicious ads and locked the compromised account, but neither Reddit nor Warner Bros. Discovery has disclosed how many users clicked the lures or were infected.[2][4][5]

The campaign relied on ClickFix, a social engineering technique that tricks victims into copying and executing attacker-supplied commands in their own terminal or command prompt, under the guise of fixing a problem or completing a routine setup step.[6][9][14] In this case, some ads led to convincing HBO-lookalike sites offering a “native” HBO Max app for macOS or a promotional download, then instructed macOS users to open Terminal and paste a command, while Windows users were told to use the Run dialog or PowerShell.[6][9] The pages framed the copy‑paste sequence as a normal installation or verification step, but the commands silently fetched and launched malware, effectively causing victims to infect themselves.[6][9][14]

PasteSwitch’s infrastructure appears to tailor payloads dynamically based on the visitor’s operating system and the lure being used, selecting different delivery chains for macOS, Windows and cryptocurrency targets.[8][9][10] On macOS, researchers observed MacSync and AMOS Helper infostealers, which go after browser credentials and profiles, Telegram data, Apple Notes, saved passwords and recovery phrases for cryptocurrency wallets, using fragmentary exfiltration techniques to evade detection.[8][9] The Windows side of the operation used an InstallFix loader that runs Amatera Stealer in memory, minimizing artifacts on disk while harvesting browser data, credentials and other sensitive information.[8][9] The same infrastructure has been tied to cryptocurrency “clippers” that monitor copied wallet addresses and swap them for attacker-controlled addresses, backed by direct-to-IP TLS connections and smart contracts on Binance Smart Chain to rotate command-and-control domains.[8][9][10]

Researchers describe PasteSwitch as one of the most sophisticated known ClickFix operations to date, combining malvertising on major platforms, highly polished fake brand pages and rapidly shifting infrastructure.[1][7][10] Recent industry analysis suggests ClickFix-style techniques have surged in prevalence, with one study finding a 517% increase in such attacks against Windows and macOS over six months, underscoring how effective copy‑paste lures have become for malware delivery.[8][14] The HBO Max incident also highlights how attackers increasingly target verified or corporate accounts to lend credibility to malicious ads, exploiting user trust in official logos and checkmarks rather than relying on obviously sketchy domains.[1][2][6]

Reddit says it discovered that an advertising account authorized to post on behalf of HBO Max was being used to distribute ads containing malicious links, prompting the platform to pull the ads, lock the account and open a security investigation.[2][4][5] Hudson Rock’s analysis of archived Reddit activity indicates the wave of 108 ClickFix ads went live over a roughly two‑day window before researchers raised the alarm, suggesting the campaign was designed for maximum reach in a compressed timeframe.[1][3][9] Warner Bros. Discovery has not publicly detailed how the account was compromised, leaving unanswered questions about whether weak credentials, stolen access tokens or third‑party marketing tools were involved.[1][4]

For defenders, the PasteSwitch episode is a reminder that a verified account or familiar brand is no guarantee of safety and that technical instructions delivered via ads or pop‑ups require heightened scrutiny.[6][9][12] Security teams should consider tightening controls around corporate social and advertising accounts, enforcing strong authentication and monitoring for unusual creative or landing pages associated with their brands, while endpoint protection and browser-level defenses can help block known PasteSwitch infrastructure and detect MacSync, AMOS Helper, Amatera and related infostealers.[1][8][9][12] At the user level, the most effective mitigation remains behavioral: resist pressure tactics in ads, avoid copy‑pasting commands from untrusted pages, and verify installation or troubleshooting steps against official documentation before running anything that touches Terminal, PowerShell or other system-level tools.[6][9][14]

References

  1. Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
  2. Un ataque ‘ClickFix’ secuestra la cuenta oficial de HBO Max en Reddit y logra que los usuarios se hackeen a sí mismos
  3. HBO Max Reddit account hijacked in PasteSwitch malware campaign
  4. Hackers Hijack HBO Max Reddit Account for Hundreds of Malware …
  5. Взлом аккаунта HBO Max на Reddit: атаки ClickFix заражают Mac и Windows
  6. ClickFix attacks are tricking Mac and Windows users into hacking themselves
  7. administrators – NCSA Webboard
  8. ClickFix-атаки на Windows и Mac выросли на 517% за полгода
  9. Compromised HBO Max Reddit Account Served PasteSwitch …
  10. InfoStealers | The all-around Infostealers hub
  11. Hackers hijack HBO Max Reddit account to spread …
  12. ClickFix-style commands disguised as tech tips across social media …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply