Key facts
- Hackers hijacked HBO Max's verified Reddit account.
- 108 malicious ads were run from the account over approximately 48 hours.
Hackers compromised HBO Max's verified Reddit account and used it to distribute 108 malicious advertisements over two days, cybersecurity experts reported. The operation, dubbed PasteSwitch, targeted Windows and Mac users with malware designed to steal sensitive information, including cryptocurrency wallet recovery phrases.

The incident highlights the risks of account takeovers and the sophisticated methods used to distribute malware, particularly targeting cryptocurrency holders. The use of a trusted brand's account and deceptive tactics like ClickFix underscore the evolving threat landscape for both consumers and businesses.
Hackers compromised the verified Reddit account of streaming service HBO Max earlier this month, using it to distribute 108 malicious advertisements over approximately two days, according to cybersecurity experts. Researchers from Hudson Rock linked the account takeover to a broader operation known as PasteSwitch, which targets Windows and Mac users with malware designed to steal sensitive information, including cryptocurrency wallet recovery phrases.
The hijacked account was used to promote a fake macOS application for HBO Max. Instructions provided via the ads directed users to paste commands into their system's Terminal, Run, or PowerShell, which could infect their computers. This technique, called ClickFix, disguises malicious commands as routine software installation or verification steps, leveraging the credibility of a recognizable company.
The PasteSwitch operation's delivery system adapts to the visitor's device and the advertised software. Observed Mac payloads included MacSync and Atomic macOS (AMOS), which steal browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases. The malware utilized Binance Smart Chain (BSC) contracts as control servers, allowing hackers to update their command server addresses. The operation also involved cryptocurrency clipboard hijackers that replace a copied wallet address with one controlled by an attacker, potentially leading users to send funds to the wrong recipient.
Reddit administrators paused the advertisements and initiated a security investigation after receiving reports, according to Malwarebytes. The exact method of the account compromise and the number of infected individuals remain unconfirmed. The investigation does not indicate a breach of HBO Max's streaming service itself, but rather a takeover of its Reddit account.