Hackers compromised HBO Max’s verified Reddit account and used its trusted identity to distribute 108 malicious advertisements over roughly 48 hours, targeting both Mac and Windows users with password-stealing and crypto-focused malware. Cybersecurity researchers have linked the attack to a broader operation called PasteSwitch, which used fake HBO Max downloads, AI tools and cryptocy wallet applications to trick victims into infecting their own computers.
The campaign was discovered after a Reddit user noticed an advertisement from the verified u/hbomax account promoting an HBO Max application for macOS.
There was one major problem: HBO Max doesn’t offer a native standalone Mac app.
Users who clicked the advertisement were directed to convincing HBO Max lookalike websites. Instead of receiving a normal application download, visitors were instructed to copy and paste a command into their computer’s Terminal.
That technique is known as ClickFix, a social-engineering attack designed to convince victims to manually execute malicious code on their own devices.
Researchers at Hudson Rock and ADAMnetworks found that the compromised account distributed 108 different malicious advertisements within approximately 48 hours.
The campaign included:
The verified HBO Max account made the advertisements particularly convincing because users had reason to believe they were coming from a legitimate company.
The campaign went beyond stealing ordinary passwords.
Researchers discovered fake cryptocy wallet applications impersonating Ledger, Trezor and Exodus. Those applications were designed to capture 12- and 24-word wallet recovery phrases, potentially giving attackers complete control over a victim’s crypto.
Other malware collected browser credentials, Telegram information, Apple Notes and stored passwords.
Windows users were targeted with separate malware capable of taking screenshots and extracting saved browser credentials.
PasteSwitch also deployed AnimateClipper and ZigClipper, malware designed specifically for cryptocy transactions.
Clipboard-stealing malware monitors when a victim copies a crypto wallet address. Before the user pastes that address into a transaction, the malware can secretly replace it with an address controlled by the attacker.
Researchers found that the operation even used smart contracts on BNB Smart Chain as part of its command-and-control infrastructure, allowing attackers to change domains used by the malware without rebuilding the entire operation.
Reddit confirmed that an HBO Max advertising account had been compromised and used to distribute malicious links.
The platform subsequently locked the account, removed the malicious advertisements and began investigating the incident. The number of users who clicked the ads or ultimately had their devices compromised remains unknown.
The HBO Max incident demonstrates why established corporate social-media accounts can be valuable targets for cybercriminals.
Instead of creating an obviously suspicious account and attempting to build credibility, attackers were able to temporarily inherit the trust associated with a verified entertainment brand and use that reputation to distribute malware.
For crypto users, the attack is another reminder that a verified account doesn’t automatically make a download safe. In this case, a trusted HBO Max account was transformed into a delivery system for malware capable of stealing passwords, seed phrases and cryptocy transactions.
Less than 24 hours after the CLARITY Act failed to clear its Senate procedural hurdle,…
Circle has officially launched the public mainnet of Arc, its new Layer 1 blockchain built…
U.S. lawmakers have advanced legislation that would turn President Donald Trump’s Strategic Bitcoin Reserve from…
Pixelmon is officially ending game development and laying off its gaming team after an external…
The CLARITY Act suffered a major setback in the U.S. Senate after lawmakers failed to…
A Zcash user says approximately $589,000 in USDT has remained inaccessible through NEAR Intents for…