Skip to content
Tech News
← Back to articles

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

read original more articles
Why This Matters

This incident highlights the growing threat of social media account hijacking used to distribute malware, emphasizing the importance of security for brand accounts. It also demonstrates how cybercriminals leverage trusted platforms to deceive users and spread sophisticated attacks like ClickFix. For consumers and companies alike, it underscores the need for vigilance and robust security measures online.

Key Takeaways

Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.

Security researchers at Hudson Rock and ADAMnetworks analyzed the campaign and say the verified u/hbomax Reddit account was hijacked and used to launch 108 malicious advertisements over about 48 hours.

The ads used a social engineering technique known as ClickFix, which tricks users into copying and pasting malicious commands into Windows Run, PowerShell, or macOS Terminal while pretending to fix an error, verify a CAPTCHA, or install legitimate software.

The type of attack has become increasingly popular among cybercriminals because victims run the malicious commands themselves using legitimate operating system tools, potentially bypassing some browser and security software designed to detect malware downloads.

While some of the advertisements pushed by the HBO Max account impersonated the streaming service, others promoted fake AI tools, developer software, and macOS utilities.

Hudson Rock and ADAMnetworks have linked the attack to a larger campaign they call PasteSwitch, which targets both Windows and macOS systems and has been used to distribute information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications.

The researchers say PasteSwitch refers to the operation's use of attacker-supplied commands that victims paste into their systems, while the attackers' backend switches between campaigns, platforms, payloads, and crypto theft methods depending on the visitor.

BleepingComputer contacted HBO and Warner Bros. Discovery with questions about the incident but has not received a response.

Fake HBO Max app delivers malware

The campaign was initially discovered after a Reddit user spotted an advertisement posted from the verified HBO Max account promoting what appeared to be a native HBO Max application for macOS.

... continue reading