Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
About
CLAY TRIBUNE.
ShopCartAccount
Advertisement

HBO Max’s Official Reddit Account Was Hijacked to Push Malware That Steals Cryptocurrency

HBO Max's verified Reddit account was hijacked to spread malware stealing passwords and crypto wallet info. The ads ran for two days.

By mitch·4 min read
A cracked digital screen displaying a Reddit login page with malicious code appearing over it.

Over a two-day period, hackers seized control of HBO Max’s verified Reddit account and posted 108 malicious advertisements. Security experts caution that these ads were designed to trick visitors into installing malware capable of stealing passwords and cryptocurrency wallet data.

Alex Cutts first flagged the takeover in the r/cybersecurity subreddit. He pointed to an official-looking Reddit advertisement from the verified u/hbomax account that pushed a native macOS app for HBO Max. That app is a fake.

The Malicious Command

Rather than offering an installer, the ad pointed visitors toward Terminal on a Mac or Run or PowerShell on Windows. It directed them to copy and paste a single command into those tools, a command capable of infecting their machine.

Advertisement

The method goes by the name ClickFix, which conceals harmful commands within what look like ordinary steps for putting software in place, correcting faults, or showing a visitor is not a machine. The account that was taken over gave those directions the weight of a familiar brand behind them.

Researchers from cybercrime intelligence firm Hudson Rock dubbed the operation “PasteSwitch.” They found that the delivery system appears to adapt to the visitor’s device and the software being advertised.

What the Malware Steals

On Apple computers, two observed payloads were found: MacSync and Atomic macOS (AMOS). Both are built to steal data from a system, taking hold of sensitive information.

The reported targets were extensive:

  • Browser credentials
  • Telegram data
  • Apple Notes
  • Saved passwords
  • Cryptocurrency wallet recovery phrases

The attackers employed Binance Smart Chain (BSC) contracts as mutable command-and-control dead drops. The malware looks up the current address of the hackers’ control server by checking these BSC contracts. When the hackers move to a new server, they can change that address, which allows the malware to continue locating it.

The wider operation was connected to clipboard hijackers tied to cryptocurrency. These tools swap a copied wallet address with one run by an attacker. A person who pastes the altered address without inspecting it might send funds to the wrong party.

Recovery phrases that get taken by others create their own danger, since they hand over full command of the wallet to whoever takes them.

The Response So Far

Malwarebytes said Reddit’s administrators stopped the advertisements and launched a security investigation following reports. The report failed to determine how the account was taken over or how many people were affected.

No proof of a breach into HBO Max’s streaming service was offered alongside the account takeover described on Reddit.

Related Campaigns

Other recent campaigns have targeted cryptocurrency users with ClickFix appearing among them. In August, researchers found nearly 2,000 compromised WordPress websites backing a malware operation that relied on fake verification prompts and was capable of stealing wallet information.

Researchers from Microsoft detailed a distinct campaign that used fake CAPTCHAs to fool Windows users into executing malicious commands, with instructions fetched via BNB Chain.

What Victims Should Check

Following the instructions in one of these ads could leave you exposed before you know it. The malware is built to take recovery phrases, which gives an attacker full command over your wallet.

It’s straightforward guidance: review your accounts. Search for any charges you didn’t authorize. Update your recovery phrases should you believe they’ve been compromised.

No victim count or confirmed cryptocurrency losses appear in the report, which serves as a reminder that many of these attacks go unreported. People often see the warning too late.

That a verified corporate account was taken over for spreading this malware is disturbing. It is the sort of attack that makes people doubt whether any online warning can be trusted.

Reddit moved fast to stop the ads, which is encouraging. Unfortunately, they ran for two full days before that happened.

The operation was sophisticated, adjusting itself to the visitor’s device and the software being advertised. It made use of Binance Smart Chain contracts as a dead drop, targeting users running both Mac and Windows systems.

This demonstrates the durability of these campaigns. Researchers discovered thousands of WordPress sites that had been compromised just a few weeks ago, and they were still carrying out the exact same activity.

The key point here is straightforward: always avoid copying commands from sources you don’t know, even when those sources appear to be official.

Questions about how HBO Max’s account was taken over remain unanswered, according to the report, with no public disclosure of the answers yet made.

For now, the best anyone can do is stay alert.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.