Cybercriminals hijacked HBO Max’s verified Reddit account to distribute 108 malicious ads, exploiting the trust associated with verified accounts to spread malware.
In a concerning incident, researchers at Hudson Rock have discovered that hackers compromised HBO Max’s official, verified Reddit account to disseminate 108 distinct malicious advertisements over a span of approximately 48 hours. These ads, which promoted downloads of HBO Max along with various AI tools, developer software, and Mac utilities, leveraged the credibility of a recognized corporate account to lower the guard of potential victims.
The incident highlights a significant cybersecurity threat: the ability of cybercriminals to exploit verified accounts to lend legitimacy to their malicious activities. This tactic demonstrates how even trusted brands can be manipulated to facilitate malware distribution, raising alarms about the security of online advertisements.
The campaign first came to light when a Reddit user noticed an advertisement from the verified u/hbomax account. The ad promoted what appeared to be a native HBO Max application for macOS, despite the fact that HBO Max does not currently offer a native app for Mac computers. Instead, the company’s support page directs Mac users to stream content directly at HBOMax.com.
Upon following the advertisement, users were led to a convincing landing page. However, instead of initiating a standard file download, the site prompted visitors to copy and paste a command into their Terminal. This request should have raised immediate red flags, as legitimate software installations do not typically require such actions.
Researchers identified the technique used in this campaign as ClickFix, which manipulates victims into executing harmful commands themselves rather than relying solely on malicious downloads. The prompts may disguise themselves as troubleshooting steps, claiming that users need to resolve a CAPTCHA issue or fix a browser problem. In this case, the attackers aimed to have victims execute code through Terminal, circumventing some security measures designed to block malicious downloads.
Hudson Rock reported that the compromised Reddit account was used to push a variety of software lures, rapidly switching between different advertisements as domains were taken down or abandoned. This adaptability underscores the attackers’ ability to exploit the credibility of a compromised account while altering the websites and software names presented to victims.
Furthermore, Hudson Rock and researchers from ADAMnetworks linked the HBO Max campaign to a broader operation known as PasteSwitch. This operation is characterized by its consistent method of having victims paste commands supplied by attackers, while the delivery system varies based on the user, platform, and campaign specifics. As a result, two individuals clicking on similar malicious ads may not necessarily be exposed to the same malware.
For Mac users, researchers identified several potential payload paths associated with PasteSwitch. These included MacSync, which could steal browser credentials, Telegram data, and macOS passwords, as well as an AMOS helper chain that could maintain access to an infected device. Additionally, the operation involved fake cryptocurrency wallet applications designed to steal recovery phrases, potentially exposing users to significant financial risks.
For Windows users, the PasteSwitch operation adapted its attack methods, utilizing mshta and PowerShell to deliver malware. One method involved disguising a malicious file as an MP3/HTA format, which could create scheduled tasks and launch PowerShell. Later stages of the attack could inject malware directly into memory without writing it to disk, complicating detection efforts.
Researchers also uncovered a connection between PasteSwitch and cryptocurrency clipboard hijackers, such as AnimateClipper and ZigClipper. These tools monitor clipboard activity and can replace cryptocurrency addresses when users copy and paste them, leading to potentially disastrous financial consequences.
The rapid evolution of these tactics highlights the need for users to remain vigilant when interacting with online advertisements. A recognizable company name or a verification badge does not guarantee the legitimacy of an ad. As demonstrated by this incident, even verified accounts can be compromised, allowing attackers to exploit consumer trust.
In response to the incident, Reddit confirmed that the HBO Max account authorized to run advertisements on its platform was compromised and used to distribute malicious links. The company stated that it has since locked the account, removed the ads, and is working with HBO Max to enhance account security. At this time, Reddit has not identified any impact on other advertising accounts on its platform.
To protect against similar threats, users are advised to take several precautions. When encountering advertisements for software, it is best to open a new browser tab and navigate directly to the company’s official website. For applications, checking the official app store on your device is recommended. If a webpage requests that you open Terminal, PowerShell, or the Run dialog to paste a command, it is crucial to close the page immediately.
Additionally, users should remain aware of security updates that can provide protections against newer attack techniques. Installing updates through operating system settings or software updaters is essential for maintaining security. Strong antivirus software can also help block malicious websites and detect malware, providing an extra layer of protection.
As cybercriminals continue to evolve their tactics, it is vital for users to adjust their instincts and remain cautious. The moment a website requests that you execute an unfamiliar command, it is imperative to stop and reassess the situation. By staying informed and vigilant, individuals can better protect themselves against the ever-changing landscape of online threats.
For further insights, refer to CyberGuy.



























































































