Hackers compromised HBO Max’s verified Reddit account and used its trusted identity to distribute 108 malicious advertisements over roughly 48 hours, targeting both Mac and Windows users with password-stealing and crypto-focused malware. Cybersecurity researchers have linked the attack to a broader operation called PasteSwitch, which used fake HBO Max downloads, AI tools and cryptocurrency wallet applications to trick victims into infecting their own computers.
Fake HBO Max App Targeted Mac Users
The campaign was discovered after a Reddit user noticed an advertisement from the verified u/hbomax account promoting an HBO Max application for macOS.
There was one major problem: HBO Max doesn’t offer a native standalone Mac app.
Users who clicked the advertisement were directed to convincing HBO Max lookalike websites. Instead of receiving a normal application download, visitors were instructed to copy and paste a command into their computer’s Terminal.
That technique is known as ClickFix, a social-engineering attack designed to convince victims to manually execute malicious code on their own devices.
Hackers Pushed 108 Malicious Ads
Researchers at Hudson Rock and ADAMnetworks found that the compromised account distributed 108 different malicious advertisements within approximately 48 hours.
The campaign included:
- 46 fake HBO Max ads
- 36 fake OpenAI Codex ads
- 15 fake macOS disk utility ads
- 11 ads impersonating other developer tools
The verified HBO Max account made the advertisements particularly convincing because users had reason to believe they were coming from a legitimate company.
Fake Crypto Wallets Tried to Steal Seed Phrases
The campaign went beyond stealing ordinary passwords.
Researchers discovered fake cryptocurrency wallet applications impersonating Ledger, Trezor and Exodus. Those applications were designed to capture 12- and 24-word wallet recovery phrases, potentially giving attackers complete control over a victim’s crypto.
Other malware collected browser credentials, Telegram information, Apple Notes and stored passwords.
Windows users were targeted with separate malware capable of taking screenshots and extracting saved browser credentials.
Crypto Clipper Could Swap Wallet Addresses
PasteSwitch also deployed AnimateClipper and ZigClipper, malware designed specifically for cryptocurrency transactions.
Clipboard-stealing malware monitors when a victim copies a crypto wallet address. Before the user pastes that address into a transaction, the malware can secretly replace it with an address controlled by the attacker.
Researchers found that the operation even used smart contracts on BNB Smart Chain as part of its command-and-control infrastructure, allowing attackers to change domains used by the malware without rebuilding the entire operation.
Reddit Locks the Account and Removes the Ads
Reddit confirmed that an HBO Max advertising account had been compromised and used to distribute malicious links.
The platform subsequently locked the account, removed the malicious advertisements and began investigating the incident. The number of users who clicked the ads or ultimately had their devices compromised remains unknown.
Trusted Accounts Are Becoming Targets
The HBO Max incident demonstrates why established corporate social-media accounts can be valuable targets for cybercriminals.
Instead of creating an obviously suspicious account and attempting to build credibility, attackers were able to temporarily inherit the trust associated with a verified entertainment brand and use that reputation to distribute malware.
For crypto users, the attack is another reminder that a verified account doesn’t automatically make a download safe. In this case, a trusted HBO Max account was transformed into a delivery system for malware capable of stealing passwords, seed phrases and cryptocurrency transactions.
- Sam Bankman Fried Withdraws New Trial Motion While Denying Ghostwriting Allegations
- Two California Teens Drive 600 Miles in Attempted $66M Bitcoin Robbery Plot
- Revolut Hackers Demand $3 Million in Monero and Threaten to Sell Customer Data
- Three UK Men Jailed After Posing as Police to Steal $5.3 Million in Cryptocurrency
- How Two U.S. Teens Ended Up in a $66 Million Crypto Heist Plot
- John Gotti’s Grandson Sentenced to Prison in $1.1 Million COVID Fraud and Crypto Scheme














































































































































