Compromised HBO Max Reddit Account Used to Spread Malware via Fake App Ads
The official HBO Max Reddit account was compromised and used to distribute more than 100 malicious ads as part of what researchers call a 48-hour 'malvertising blitz'. The ads promoted a fake macOS app for HBO Max, a client the streaming service does not actually offer, and directed clicks to a convincing lookalike website.
Visitors who clicked through were prompted to copy and paste a command into their Mac's Terminal, a classic 'ClickFix' technique used to trick users into manually running malicious code that bypasses normal security warnings. Reddit paused the ads after being alerted and said its safety teams were investigating, but it is not yet known how the HBO Max account was taken over.
Security researchers at Hudson Rock and ADAMnetworks say the incident was part of a broader campaign, dubbed PasteSwitch, that pushed 108 different malicious ads tailored to victims' operating systems. Payloads included infostealers, malware loaders, fake cryptocurrency wallet apps, and cryptocurrency 'clippers' that hijack transactions, some of which used blockchain smart contracts to keep their command servers running even if taken down.