Cybercriminals hijacked the verified HBO Max Reddit account to launch a 48-hour malvertising campaign, tricking users into installing information-stealing malware via deceptive ClickFix social engineering tactics.
Key Points
- Attackers used the compromised u/hbomax account to push 108 malicious ads over two days, targeting both macOS and Windows users.
- The campaign, dubbed PasteSwitch, utilized fake lures for HBO Max, OpenAI Codex, and various developer tools to distribute infostealers.
- Victims were prompted to run malicious commands that installed payloads like MacSync, AMOS, and Amatera to harvest credentials and cryptocurrency.
- The operation employed blockchain-hosted smart contracts on the Binance Smart Chain to dynamically rotate command-and-control infrastructure and evade detection.
- Security researchers at Hudson Rock and ADAMnetworks identified that the delivery system also mimicked legitimate software like Homebrew, GitHub, and various crypto wallets.