HBO Max Reddit Account Hijacked for Malware and Crypto Stealing
HBO Max's official Reddit account was hijacked by malicious actors who used it to spread 108 malware and crypto-stealing ads in a mere 48 hours. The attack, which has been linked to a broader campaign called PasteSwitch, aimed to drain cryptocurrency wallets by stealing seed phrases and clipboard-hijacking wallet addresses.
The attackers employed a social-engineering technique called ClickFix, which tricks users into manually executing commands on their terminal or command prompt. This allowed them to install infostealers like MacSync and AMOS on victims' machines without raising any red flags.
While the campaign was eventually shut down by Reddit's moderation team, its persistence since early 2026 suggests that it is an ongoing enterprise with a well-coordinated team behind it. The PasteSwitch infrastructure allows for quick changes in domains and device-specific payloads, making it difficult to track and stop.