Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
AI Summary
Hackers hijacked HBO Max's verified Reddit account (u/hbomax) to distribute malicious advertisements as part of a campaign dubbed PasteSwitch. These ads used ClickFix social engineering tactics, tricking users into pasting malicious commands into Windows Run, PowerShell, or macOS Terminal under the guise of installing legitimate software or fixing errors. The attack distributed information-stealing malware such as MacSync and AMOS helper on macOS, and PowerShell-based payloads on Windows, including memory-resident Amatera Stealer. Attackers used domains like hbomaxx[.]us and infrastructure including ember-bridge[.]com to deliver payloads and rotate between campaigns targeting both general users and developers.
AI-extracted · verify before operational use