AUTO-UPDATED

Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz

Cybercriminals hijacked the verified HBO Max Reddit account to launch a 48-hour malvertising campaign, tricking users into installing information-stealing malware via deceptive ClickFix social engineering tactics.

Key Points

  • Attackers used the compromised u/hbomax account to push 108 malicious ads over two days, targeting both macOS and Windows users.
  • The campaign, dubbed PasteSwitch, utilized fake lures for HBO Max, OpenAI Codex, and various developer tools to distribute infostealers.
  • Victims were prompted to run malicious commands that installed payloads like MacSync, AMOS, and Amatera to harvest credentials and cryptocurrency.
  • The operation employed blockchain-hosted smart contracts on the Binance Smart Chain to dynamically rotate command-and-control infrastructure and evade detection.
  • Security researchers at Hudson Rock and ADAMnetworks identified that the delivery system also mimicked legitimate software like Homebrew, GitHub, and various crypto wallets.

Why it Matters

This incident highlights the growing risk of "trusted" advertising channels being weaponized to bypass traditional security filters and user skepticism. By compromising verified accounts, attackers can effectively distribute malware to a broad audience, demonstrating the need for more robust account security and stricter verification processes on social media platforms.
Help Net Security Published by Sinisa Markovic
Read original