BTC $75,653.03 -0.25%
ETH $2,395.30 -0.28%
BNB $716.16 -0.40%
XRP $1.29 -0.71%
SOL $97.73 -0.14%
TRX $0.3353 +0.79%
DOGE $0.0800 -1.01%
ADA $0.1922 -2.62%
BCH $217.42 +0.16%
LINK $10.87 -2.05%
HYPE $77.81 +1.67%
AAVE $115.58 -6.54%
SUI $0.6991 +1.64%
XLM $0.1801 -0.14%
ZEC $1,287.83 +13.11%
AAPL $332.01 +0.47%
AMZN $245.40 -0.96%
GOOGL $342.78 -0.44%
MSFT $489.29 -1.47%
META $673.47 +0.69%
NVDA $213.90 +0.83%
TSLA $358.13 +0.82%
SNDK $1,521.38 -0.72%
INTC $100.45 +3.13%
SPCX $150.25 +4.40%
MU $923.55 -0.22%
AMD $512.10 +1.47%
BTC $75,653.03 -0.25%
ETH $2,395.30 -0.28%
BNB $716.16 -0.40%
XRP $1.29 -0.71%
SOL $97.73 -0.14%
TRX $0.3353 +0.79%
DOGE $0.0800 -1.01%
ADA $0.1922 -2.62%
BCH $217.42 +0.16%
LINK $10.87 -2.05%
HYPE $77.81 +1.67%
AAVE $115.58 -6.54%
SUI $0.6991 +1.64%
XLM $0.1801 -0.14%
ZEC $1,287.83 +13.11%
AAPL $332.01 +0.47%
AMZN $245.40 -0.96%
GOOGL $342.78 -0.44%
MSFT $489.29 -1.47%
META $673.47 +0.69%
NVDA $213.90 +0.83%
TSLA $358.13 +0.82%
SNDK $1,521.38 -0.72%
INTC $100.45 +3.13%
SPCX $150.25 +4.40%
MU $923.55 -0.22%
AMD $512.10 +1.47%
first_img

HBO Max account was hijacked, and 108 malicious ads were placed to steal cryptocurrency assets

2026-09-17 01:14:35

Cybersecurity company Hudson Rock disclosed that the Reddit verified account of the streaming service HBO Max was hijacked earlier this month and deployed 108 malicious ads within approximately 48 hours. These ads used a non-existent HBO Max native macOS application as bait, luring users to open Terminal or PowerShell and paste malicious commands, a technique known as ClickFix.

Researchers named this operation PasteSwitch, and its delivery system adapts based on the visitor's device and the advertised software. Observed Mac payloads include MacSync and Atomic macOS (AMOS) information-stealing trojans, targeting browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases. The malware also utilized Binance Smart Chain contracts as variable C2 address delivery points and was associated with a cryptocurrency clipboard hijacker that replaces clipboard wallet addresses.

According to Malwarebytes, Reddit administrators have suspended the related ads and initiated a security investigation following reports. The report did not specify how the account was compromised or the number of victims, nor was there evidence found that the HBO Max streaming service itself was breached. The ClickFix technique has previously been used multiple times in attacks targeting cryptocurrency users, including approximately 2,000 compromised WordPress sites and malicious activities disguised as CAPTCHA.

app_icon
ChainCatcher Building the Web3 world with innovations.