NewsCryptoHackers Hijack HBO Max's Verified Reddit Account to Spread Crypto-Stealing Malware

Hackers Hijack HBO Max's Verified Reddit Account to Spread Crypto-Stealing Malware

Author: Decrypt·

Key Takeaways

  • Attackers used the compromised verified u/hbomax Reddit account to run 108 malicious advertisements over approximately 48 hours through Reddit's own advertising platform.
  • The operation, dubbed PasteSwitch by researchers, promoted a nonexistent native macOS HBO Max app and used the ClickFix technique to trick visitors into pasting malicious commands into Terminal on Macs or Run and PowerShell on Windows.
  • Observed Mac payloads included MacSync and Atomic macOS (AMOS) information stealers, which targeted browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases.
  • The malware used Binance Smart Chain contracts as mutable command-and-control dead drops, allowing hackers to update server addresses, and the broader operation was linked to clipboard hijackers that replace copied wallet addresses with attacker-controlled ones.
  • Reddit administrators paused the ads and launched a security investigation, but the report did not establish how the account was compromised or how many people were infected, and it presented no evidence of a breach of HBO Max's streaming service.
Hackers Hijack HBO Max's Verified Reddit Account to Spread Crypto-Stealing Malware

Hackers hijacked the verified Reddit account of streaming service HBO Max earlier this month and used it to run 108 malicious advertisements over roughly 48 hours, cybersecurity researchers warn.

In a report published Monday, researchers at cybercrime intelligence firm Hudson Rock tie the account takeover to a broader operation targeting passwords and cryptocurrency wallet information. According to a report from cybersecurity firm Malwarebytes, Reddit administrators paused the advertisements and opened a security investigation after receiving reports. Because the ads ran through Reddit's own advertising system under a verified handle, the episode is a reminder that a verification badge and paid placement reflect control of an account at a given moment — not that everything an account promotes is safe.

"The incident was brought to light by Alex Cutts in the r/cybersecurity subreddit. While browsing the platform, they encountered an official Reddit advertisement authored by the verified u/hbomax account," Hudson Rock wrote. "The ad aggressively promoted a native macOS application for HBO Max, a standalone application that not currently exist."

Rather than providing an installer, the promoted site instructed visitors to open Terminal on a Mac, or Run or PowerShell on Windows, and paste a command that could infect their computer. The technique, known as ClickFix, disguises malicious commands as routine steps for installing software, fixing errors, or proving a visitor is human. The hijacked account lent those instructions the apparent backing of a recognizable brand.

Researchers dubbed the operation "PasteSwitch," warning that its delivery system appears to adapt to the visitor's device and the software being advertised.

Observed Mac payloads included MacSync and Atomic macOS (AMOS), information-stealing malware designed to exfiltrate sensitive data. Reported targets included browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases.

"These clippers utilized Binance Smart Chain (BSC) contracts as mutable C2 dead drops," researchers wrote, explaining that the malware checks Binance Smart Chain contracts for the latest address of the hackers' control server. Hackers can update that address whenever they switch servers, allowing the malware to keep locating its command infrastructure.

The broader operation was also linked to cryptocurrency clipboard hijackers, which replace a copied wallet address with one controlled by an attacker. A victim who pastes the substituted address without checking it could send funds to the wrong recipient. Stolen recovery phrases pose a separate risk because they can give attackers control of the associated wallet.

The report did not establish how the Reddit account was compromised or how many people were infected, and victim counts and cryptocurrency losses remain unconfirmed. It described a Reddit account takeover, with no evidence presented of a breach of HBO Max's streaming service. The findings of Reddit's security investigation could clarify the open questions of how the account was compromised and how far the campaign reached.

ClickFix has appeared in other recent campaigns targeting cryptocurrency users. In August, researchers identified nearly 2,000 compromised WordPress websites supporting a malware operation that used fake verification prompts and could steal wallet information. Microsoft researchers also described a separate campaign using fake CAPTCHAs to trick Windows users into running malicious commands, with instructions retrieved through BNB Chain. With the HBO Max campaign, the same technique has now been documented across compromised websites, fake CAPTCHA pages, and paid advertising on a verified social media account, spanning very different kinds of delivery infrastructure.