Post

HBO Max's Verified Reddit Account Hijacked to Spread Malware

HBO Max's Verified Reddit Account Hijacked to Spread Malware

HBO Max’s Verified Reddit Account Hijacked to Spread Malware 🚨

Researchers at Hudson Rock have discovered that cybercriminals hijacked HBO Max’s verified Reddit account and used it to run 108 malicious ads over roughly 48 hours. These ads exploited HBO Max’s trusted corporate account to promote fake AI tools, developer software, and macOS utilities, lowering potential victims’ guards. Some ads directed users to convincing HBO lookalike sites that claimed to offer a native HBO Max app for macOS or a promotional download. However, instead of providing an installer, these sites instructed visitors to open Terminal on their Mac or, on Windows, the Run dialog or PowerShell, and paste in a command.

This tactic is part of a growing social engineering technique known as ClickFix. ClickFix attacks disguise malicious instructions as routine technical steps, such as fixing an error, completing a CAPTCHA, verifying that you are human, or installing software. A web page may silently copy a command to the clipboard and then guide the victim through pasting and executing it, leading to the infection of their own device. Researchers at ADAMnetworks have dubbed the operation behind the HBO Max ads PasteSwitch. Its infrastructure appears to tailor the next stage to the visitor’s device and the lure being used. Reportedly, ClickFix was responsible for more than half of all malware loader activity in 2025. One reason for its success is that campaigns continue to add new methods for tricking users and different commands to avoid detection.

Observed macOS payloads included MacSync and AMOS infostealers, designed to steal browser credentials, profiles, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases. Windows users could end up with the Amatera infostealer, which runs in memory. The operation has also been linked to cryptocurrency clipboard hijackers, which monitor copied wallet addresses and replace them with an attacker-controlled address before a transaction is sent. Reddit admins paused the ads and opened a security investigation after reports came in, but it is crucial to remain vigilant.

Stay Safe! 🛡️

To protect yourself, treat ads with caution; a verified account does not guarantee that an ad is safe. Always visit the company’s official website directly instead of downloading software through an advertisement. Take your time and avoid rushing to follow instructions on a webpage, especially if it asks you to run commands or copy-paste code. Never execute code or commands copied from websites, emails, ads, or messages unless you trust the source and understand what the command does. Secure your devices with an up-to-date, real-time anti-malware solution that includes web protection. Additionally, educate yourself on evolving attack techniques; understanding that attacks may come from unexpected vectors and evolve helps maintain vigilance.

Read full article

This post is licensed under CC BY 4.0 by the author.