Summary
- HBO Max’s compromised Reddit account disseminated 108 harmful ads in a span of about 48 hours.
- Malwarebytes traced these ads back to an operation named PasteSwitch, which aims at stealing information from Windows and Mac users.
- Reddit has suspended the ads and launched an investigation; however, the number of victims and the extent of cryptocurrency losses are still unverified.
Earlier this month, hackers took control of HBO Max’s verified Reddit account, exploiting it to post 108 malicious advertisements over two days, according to cybersecurity experts.
A report released on Monday by Hudson Rock, a cybercrime intelligence firm, connects this account breach to a larger effort focused on pilfering passwords and cryptocurrency wallet details.
Myriad: Who will be the top Spotify artist of 2026? Click to make your prediction.“The incident was highlighted by Alex Cutts in the r/cybersecurity subreddit. While navigating the platform, they stumbled upon an official Reddit ad from the verified account u/hbomax,” noted Hudson Rock. “The ad aggressively promoted a fictitious native macOS application for HBO Max.”
Instead of offering a legitimate installer, the link directed users to open Terminal on Mac or Run/PowerShell on Windows and paste a command that could compromise their devices.
This method, termed ClickFix, camouflages harmful commands as standard procedures for software installation, troubleshooting, or validating human users. The compromised account lent credibility to these misleading instructions.
Researchers have named this campaign “PasteSwitch,” cautioning that its delivery mechanism seems to adjust based on the visitor's device and the software being promoted.
Among the harmful payloads detected on Mac were MacSync and Atomic macOS (AMOS), both designed to extract sensitive data. Reported targets included credentials from browsers, Telegram information, Apple Notes, saved passwords, and recovery phrases for cryptocurrency wallets.
“These clippers utilized Binance Smart Chain (BSC) contracts as adaptable C2 dead drops,” the researchers explained, stating that the malware checks BSC contracts for updated hacker control server addresses. This allows hackers to change their server address while keeping the malware functional.
The wider operation has also been associated with clipboard hijackers that swap a copied wallet address with one controlled by the attacker. If a victim pastes this altered address without verifying it, they could inadvertently send funds to the wrong destination. Stolen recovery phrases pose an additional threat as they can grant attackers access to the associated wallet.
According to cybersecurity firm Malwarebytes, Reddit administrators have halted the ads and initiated a security investigation following multiple reports. However, the report did not clarify how the account was compromised or how many individuals were affected. It noted a Reddit account takeover but provided no evidence of a breach involving HBO Max’s streaming service.
ClickFix has been observed in other recent efforts targeting cryptocurrency users. In August, researchers identified nearly 2,000 compromised WordPress sites involved in a malware scheme that utilized fake verification prompts to steal wallet information.
Additionally, Microsoft researchers described a separate initiative that employed fake CAPTCHAs to deceive Windows users into executing malicious commands, with instructions sourced from BNB Chain.
