Hackers Use HBO Max's Reddit Account to Spread Malware
Hackers hijacked HBO Max's verified Reddit account and used it to run over 100 malicious advertisements in two days, targeting Windows and Mac users with information-stealing malware.
The operation, dubbed 'PasteSwitch,' involved ads that instructed visitors to open Terminal or PowerShell and paste a command that could infect their computer. The technique, known as ClickFix, disguises malicious commands as routine steps for installing software or proving a visitor is human.
Researchers from Hudson Rock linked the account takeover to a broader operation targeting passwords and cryptocurrency wallet information. The malware, which included MacSync and Atomic macOS (AMOS), was designed to steal sensitive information such as browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases.
The hijacked account also gave visitors instructions on how to use Binance Smart Chain contracts as mutable C2 dead drops. Hackers can update the address of their control server using these contracts, allowing the malware to find them even if they switch servers. The operation also included cryptocurrency clipboard hijackers that replace a copied wallet address with one controlled by an attacker.