HBO Max Reddit Hijacked to Spread Crypto-Stealing Malware — SkimNews

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- HBO Max's verified Reddit account (u/hbomax) was hijacked and ran 108 malicious ads over roughly 48 hours, promoting a fake "native macOS application for HBO Max" that does not actually exist.
- Hudson Rock attributed the takeover to "PasteSwitch," a ClickFix-style campaign that instructs victims to paste malicious commands into Terminal on Mac or Run/PowerShell on Windows.
- MacSync and AMOS info-stealer payloads targeted browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases.
- The malware used Binance Smart Chain contracts as mutable C2 dead drops, letting attackers swap control server addresses while infected machines kept finding them.
- The same operation included cryptocurrency clipboard hijackers that replace a copied wallet address with one controlled by the attacker before a transaction is sent.
- Reddit paused the ads and opened a security investigation after Malwarebytes flagged them; how the account was compromised and how many users were infected remain unconfirmed.
- ClickFix has surfaced in other recent campaigns, including nearly 2,000 compromised WordPress sites pushing fake verification prompts in August and a Microsoft-documented fake-CAPTCHA scheme on Windows.
Why it matters: HBO Max's verified Reddit badge gave attackers two days of trusted distribution for malware aimed at crypto holders and password vaults. Reddit paused the ads only after Malwarebytes reported them, and the platform has yet to disclose how the verified account was compromised, leaving Reddit's verified-account security model under fresh scrutiny while victim counts stay unknown.
Ask SkimNews



