general

Hackers Hijack HBO Max’s Reddit Account to Spread Crypto-Stealing Malware

September 16, 20265:06 PM
Hackers Hijack HBO Max’s Reddit Account to Spread Crypto-Stealing Malware

- HBO Max’s hijacked Reddit account ran 108 malicious ads over roughly 48 hours.

- Malwarebytes linked the ads to PasteSwitch, an operation targeting Windows and Mac users with information-stealing malware.

- Reddit paused the ads and opened an investigation; victim counts and cryptocurrency losses remain unconfirmed.

In its report on Monday, researchers from cybercrime intelligence firm Hudson Rock link the account takeover to a broader operation targeting passwords and cryptocurrency wallet information.

Instead of providing an installer, the site instructed visitors to open Terminal on a Mac, or Run or PowerShell on Windows, and paste a command that could infect their computer.

The technique, known as ClickFix, disguises malicious commands as routine steps for installing software, fixing errors, or proving a visitor is human. The hijacked account gave those instructions the apparent backing of a recognizable company.

Researchers dubbed the operation “PasteSwitch,” warning that its delivery system appears to adapt to the visitor’s device and the software being advertised.

Observed Mac payloads included MacSync and Atomic macOS (AMOS), information-stealer malware designed to steal sensitive information. Reported targets included browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases.

“These clippers utilized Binance Smart Chain (BSC) contracts as mutable C2 dead drops,” researchers wrote, explaining that the malware checks Binance Smart Chain contracts for the latest address of the hackers’ control server. Hackers can then update that address when they switch servers, allowing the malware to keep finding them.

The broader operation was also linked to cryptocurrency clipboard hijackers, which replace a copied wallet address with one controlled by an attacker. A victim who pastes the substituted address without checking it could send funds to the wrong recipient. Stolen recovery phrases pose a separate risk because they can give attackers control of the associated wallet.

ClickFix has appeared in other recent campaigns targeting cryptocurrency users. In August, researchers identified nearly 2,000 compromised WordPress websites supporting a malware operation that used fake verification prompts and could steal wallet information.

Microsoft researchers also described a separate campaign using fake CAPTCHAs to trick Windows users into running malicious commands, with instructions retrieved through BNB Chain.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Disclaimer

This article is for informational purposes only. Cryptocurrency markets are highly volatile and involve significant risk. BlockchainNewsUAE does not provide investment advice. Always conduct your own research before making any financial decisions.