Hackers Hijack HBO Max Reddit Account to Spread Info-Stealing Malware

Cybercriminals hijack the verified HBO Max Reddit account, u/hbomax, and use it to publish 108 malicious advertisements over roughly 48 hours. The ads launch ClickFix attacks, a social engineering technique that tricks users into copying and pasting malicious commands into Windows Run, PowerShell, or macOS Terminal under the pretense of fixing an error, verifying a CAPTCHA, or installing legitimate software. Security researchers at Hudson Rock and ADAMnetworks analyze the campaign and warn that this method is growing in popularity because victims execute the malicious commands themselves using legitimate operating system tools, which can bypass browser protections and security software.

While some ads impersonate the HBO Max streaming service, including a fake native macOS app hosted on a lookalike domain, others promote fake AI tools, developer software, and macOS utilities. The campaign is discovered after a Reddit user notices an advertisement from the verified HBO Max account promoting a macOS HBO Max app and alerts the community. The researchers link the activity to a larger operation they call PasteSwitch, which targets both Windows and macOS systems and distributes information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications.

PasteSwitch gets its name from attackers supplying commands that victims paste into their own systems, while the backend infrastructure switches between campaigns, platforms, payloads, and crypto theft methods depending on the visitor. BleepingComputer contacts HBO and Warner Bros. Discovery with questions about the incident but does not receive a response. The incident highlights the growing risk of compromised verified brand accounts being used to lend credibility to malware campaigns on popular platforms.

Read More at the original source →