HBO Max Reddit Account Compromised, Used to Distribute Malware via ClickFix Attacks
Hackers successfully compromised the official HBO Max Reddit account (u/hbomax) and utilized it to launch a malvertising campaign. Over approximately 48 hours, 108 malicious advertisements were pushed across five different lure groups. These ads employed a social engineering tactic known as ClickFix, which deceives users into copying and pasting malicious commands into their operating system's command-line interfaces, such as Windows Run, PowerShell, or macOS Terminal. The campaign, identified by security researchers at Hudson Rock and ADAMnetworks as 'PasteSwitch,' targeted both Windows and macOS users. Some advertisements impersonated HBO Max, promoting a non-existent native macOS application, while others pushed fake AI tools, developer software, and macOS utilities. Users who clicked these ads were redirected to convincing fake websites, like hbomaxx[.]us, which then instructed them to execute commands to 'download' software, ultimately installing information-stealing malware. The malicious activity wa...