What's Happening?
Hackers successfully compromised the official HBO Max Reddit account (u/hbomax) and utilized it to launch a malvertising campaign. Over approximately 48 hours, 108 malicious advertisements were pushed across five different lure groups. These ads employed
a social engineering tactic known as ClickFix, which deceives users into copying and pasting malicious commands into their operating system's command-line interfaces, such as Windows Run, PowerShell, or macOS Terminal. The campaign, identified by security researchers at Hudson Rock and ADAMnetworks as 'PasteSwitch,' targeted both Windows and macOS users. Some advertisements impersonated HBO Max, promoting a non-existent native macOS application, while others pushed fake AI tools, developer software, and macOS utilities. Users who clicked these ads were redirected to convincing fake websites, like hbomaxx[.]us, which then instructed them to execute commands to 'download' software, ultimately installing information-stealing malware. The malicious activity was reported to Reddit, which subsequently paused the ads.
Why It's Important?
This incident highlights a growing and concerning trend in cyberattacks where legitimate, verified accounts of major brands are hijacked to distribute malware. The use of social engineering techniques like ClickFix is particularly effective because it bypasses traditional security measures that detect malware downloads, as victims are tricked into executing the malicious code themselves. The 'PasteSwitch' campaign's ability to target both Windows and macOS systems, and to switch between various payloads including information stealers, cryptocurrency clippers, and fake wallet applications, demonstrates a sophisticated and adaptable threat. The compromise of a high-profile account like HBO Max's Reddit page can erode user trust in official brand communications and platforms. Furthermore, the distribution of malware capable of stealing browser credentials, Telegram data, Apple Notes, macOS passwords, and cryptocurrency recovery phrases poses significant financial and privacy risks to affected individuals.
What's Next?
HBO and Warner Bros. Discovery have been contacted regarding the incident, but no response has been received yet. It remains unclear how the hackers gained access to the HBO Max Reddit account and whether other accounts or systems belonging to HBO or Warner Bros. Discovery were affected. Users who may have interacted with these malicious advertisements should immediately check their systems for malware and change any compromised credentials. Reddit has already taken action by pausing the malicious ads. The broader cybersecurity community will likely continue to analyze the PasteSwitch campaign to understand its full scope and develop more robust defenses against such sophisticated social engineering and malware distribution tactics. This incident may prompt other major brands to review and strengthen the security protocols for their social media and online accounts to prevent similar compromises.
Beyond the Headlines
The 'PasteSwitch' campaign, as demonstrated by the HBO Max Reddit account compromise, reveals a deeper shift in cybercriminal strategies. Instead of relying solely on technical vulnerabilities, attackers are increasingly leveraging human psychology and trust in established brands. The ClickFix method, where users are coaxed into executing commands, exploits a common user behavior: following instructions to resolve perceived issues or access desired content. This blurs the line between legitimate system operations and malicious activity, making detection more challenging for both users and automated security systems. The campaign's versatility in targeting different operating systems and distributing various types of malware, including cryptocurrency wallet stealers, underscores the financial motivations driving these attacks. This incident serves as a stark reminder that even verified accounts can be weaponized, necessitating a heightened level of skepticism and vigilance from users when interacting with online content, even from seemingly official sources.













