Hackers Hijack HBO Max’s Reddit Account to Spread Crypto-Stealing Malware — SkimNews

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- HBO Max's verified Reddit account (u/hbomax) was hijacked and used to run 108 malicious ads over roughly 48 hours, promoting a standalone macOS application that does not actually exist
- Hudson Rock linked the operation to "PasteSwitch," a campaign using the ClickFix technique that disguises malicious commands as routine steps like software installation or human verification prompts
- Mac payloads observed included MacSync and Atomic macOS (AMOS) information-stealers targeting browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases
- The malware used Binance Smart Chain (BSC) contracts as mutable C2 dead drops, letting attackers update their control-server address while infected machines kept finding them
- The broader operation was also tied to cryptocurrency clipboard hijackers that swap a copied wallet address with one controlled by the attacker, sending funds to the wrong recipient
- Reddit paused the ads and opened a security investigation after receiving reports, though researchers did not establish how the account was compromised or how many users were infected
- Malwarebytes confirmed the incident was a Reddit account takeover with no evidence presented of any breach of HBO Max's streaming service itself
Why it matters: The hijack weaponized Reddit's verified-account trust signal — 108 ads carrying HBO Max's blue-checkmark endorsement ran for two days before being flagged, and the ClickFix technique targets both Windows and Mac users with payloads specifically built to drain crypto wallets and saved passwords. The technique adapts to the visitor's device and the software being advertised, making verified brand ad slots a high-leverage delivery channel for information-stealers.
Ask SkimNews



