Crime

Hackers Hijack HBO Max Reddit Account to Spread Crypto-Stealing Malware

Hackers compromised HBO Max’s verified Reddit account and used its trusted identity to distribute 108 malicious advertisements over roughly 48 hours, targeting both Mac and Windows users with password-stealing and crypto-focused malware. Cybersecurity researchers have linked the attack to a broader operation called PasteSwitch, which used fake HBO Max downloads, AI tools and cryptocy wallet applications to trick victims into infecting their own computers.

Fake HBO Max App Targeted Mac Users

The campaign was discovered after a Reddit user noticed an advertisement from the verified u/hbomax account promoting an HBO Max application for macOS.

There was one major problem: HBO Max doesn’t offer a native standalone Mac app.

Users who clicked the advertisement were directed to convincing HBO Max lookalike websites. Instead of receiving a normal application download, visitors were instructed to copy and paste a command into their computer’s Terminal.

That technique is known as ClickFix, a social-engineering attack designed to convince victims to manually execute malicious code on their own devices.

Hackers Pushed 108 Malicious Ads

Researchers at Hudson Rock and ADAMnetworks found that the compromised account distributed 108 different malicious advertisements within approximately 48 hours.

The campaign included:

  • 46 fake HBO Max ads
  • 36 fake OpenAI Codex ads
  • 15 fake macOS disk utility ads
  • 11 ads impersonating other developer tools

The verified HBO Max account made the advertisements particularly convincing because users had reason to believe they were coming from a legitimate company.

Fake Crypto Wallets Tried to Steal Seed Phrases

The campaign went beyond stealing ordinary passwords.

Researchers discovered fake cryptocy wallet applications impersonating Ledger, Trezor and Exodus. Those applications were designed to capture 12- and 24-word wallet recovery phrases, potentially giving attackers complete control over a victim’s crypto.

Other malware collected browser credentials, Telegram information, Apple Notes and stored passwords.

Windows users were targeted with separate malware capable of taking screenshots and extracting saved browser credentials.

Crypto Clipper Could Swap Wallet Addresses

PasteSwitch also deployed AnimateClipper and ZigClipper, malware designed specifically for cryptocy transactions.

Clipboard-stealing malware monitors when a victim copies a crypto wallet address. Before the user pastes that address into a transaction, the malware can secretly replace it with an address controlled by the attacker.

Researchers found that the operation even used smart contracts on BNB Smart Chain as part of its command-and-control infrastructure, allowing attackers to change domains used by the malware without rebuilding the entire operation.

Reddit Locks the Account and Removes the Ads

Reddit confirmed that an HBO Max advertising account had been compromised and used to distribute malicious links.

The platform subsequently locked the account, removed the malicious advertisements and began investigating the incident. The number of users who clicked the ads or ultimately had their devices compromised remains unknown.

Trusted Accounts Are Becoming Targets

The HBO Max incident demonstrates why established corporate social-media accounts can be valuable targets for cybercriminals.

Instead of creating an obviously suspicious account and attempting to build credibility, attackers were able to temporarily inherit the trust associated with a verified entertainment brand and use that reputation to distribute malware.

For crypto users, the attack is another reminder that a verified account doesn’t automatically make a download safe. In this case, a trusted HBO Max account was transformed into a delivery system for malware capable of stealing passwords, seed phrases and cryptocy transactions.

Terron Gold

Recent Posts

House Advances Sweeping Crypto Tax Bill After CLARITY Act Setback

Less than 24 hours after the CLARITY Act failed to clear its Senate procedural hurdle,…

15 hours ago

Circle Launches Arc Mainnet With BlackRock and Visa as Validators

Circle has officially launched the public mainnet of Arc, its new Layer 1 blockchain built…

16 hours ago

House Panel Advances Bill to Lock U.S. Bitcoin Reserve Into Law For 20 Years

U.S. lawmakers have advanced legislation that would turn President Donald Trump’s Strategic Bitcoin Reserve from…

16 hours ago

Pixelmon Shuts Down Game Development After Years of Trying to Recover

Pixelmon is officially ending game development and laying off its gaming team after an external…

21 hours ago

CLARITY Act Stalls After Senate Vote Falls Short

The CLARITY Act suffered a major setback in the U.S. Senate after lawmakers failed to…

1 day ago

Zcash User Says $589K in USDT Has Been Stuck on NEAR Intents for 50 Days

A Zcash user says approximately $589,000 in USDT has remained inaccessible through NEAR Intents for…

2 days ago