Hackers took over HBO Max’s verified Reddit account and used it to distribute 108 malicious advertisements over roughly 48 hours, according to reporting highlighted by Malwarebytes. Reddit has since paused the ads and said it opened an investigation, while the number of people affected and any cryptocurrency losses remain unconfirmed.

The campaign stood out because it used a trusted brand account to promote fake software downloads. Researchers linked the activity to an operation they call PasteSwitch, which targeted both Mac and Windows users with information-stealing malware.

Fake app lure used trusted HBO Max branding

The incident surfaced after Alex Cutts drew attention to it in the r/cybersecurity subreddit. The ads appeared through HBO Max’s verified Reddit account, giving the campaign an appearance of legitimacy that could have made users more likely to click.

The promoted product was described as a native macOS application for HBO Max, but no such app exists. Rather than providing a normal installer, the pages shown to visitors instructed them to manually paste commands into their systems.

Users were told to run commands themselves

On Mac, visitors were prompted to open Terminal and paste a command. Windows users were directed to Run or PowerShell for the same basic step. That approach can bypass expectations users may have around conventional software installation and instead turns the victim into the one executing the infection chain.

Malwarebytes said the delivery method appeared to change depending on the device being used and the software being impersonated. Researchers referred to this broader setup as PasteSwitch.

Mac payloads aimed at credentials and wallet data

Observed Mac payloads included MacSync and Atomic macOS, also known as AMOS. These are information stealers built to collect sensitive data from infected systems rather than simply disrupt them.

According to the researchers, the malware can target credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases. That combination makes the campaign relevant not only as a cybersecurity incident but also as a potential threat to digital asset holders, even though no confirmed crypto losses have been reported in this case.

Researchers noted blockchain-based control method

Malwarebytes said the malware used mutable Binance Smart Chain contracts as command-and-control dead drops. In practice, that let the attackers update the address being used and maintain control over the operation.

The use of that mechanism adds another layer to the campaign’s design, pairing social engineering through a recognizable media brand with infrastructure intended to stay flexible while the ads remained active.

Reddit investigation is underway

Reddit paused the malicious advertisements after the activity was identified and opened an investigation. For now, the confirmed facts center on the account compromise, the 108 ads, the roughly two-day window, and the malware delivery method described by researchers.

What remains unclear is the scope of the damage. Neither the number of victims nor any resulting cryptocurrency theft has been confirmed, making Reddit’s investigation the next concrete step in establishing how far the campaign reached.

Source: decrypt.co