Hijacked HBO Max Reddit account used to spread malware
Cybercriminals hijacked HBO Max's verified Reddit account to run a 48-hour malvertising campaign that delivered information-stealing malware to macOS and Windows users, according to security researchers. The operation, dubbed PasteSwitch, was identified by researchers at Hudson Rock and ADAMnetworks, who reported that the attackers used the trusted corporate account to post 108 malicious advertisements over roughly two days. The campaign exploited a social engineering technique known as ClickFix, which tricks users into copying and pasting malicious commands into their system's terminal or command prompt. The ads promoted fake software, including a purported native HBO Max application for macOS, even though the streaming service does not offer one. Users who clicked were directed to convincing lookalike websites that instructed them to paste a command to "install" the software, which instead installed malware. Researchers said the malware was tailored to the victim's operating system. On macOS, payloads included infostealers such as MacSync and AMOS, designed to steal browser credentials, Telegram data, Apple Notes, and cryptocurrency wallet recovery phrases.