Urgent.News

What's breaking now, across thousands of outlets.

Science

HBO Max Reddit account compromised to serve ClickFix attacks

Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware

HBO Max Reddit account compromised to serve ClickFix attacks

On September 6, a Reddit user discovered malicious ads on the official HBO Max Reddit account. The ads showcased a macOS app for HBO Max, despite the streaming service not offering one. Users who clicked on the ad were redirected to a landing page (hbomaxx.us) with a join/download button. Clicking the button prompted users to copy and paste a command into Terminal on macOS, a tactic known as ClickFix.

The Reddit user suspected the account had been compromised and reported the issue. Three days later, Reddit paused the ads, and an admin stated that their security and safety teams were investigating.

Researchers at Hudson Rock and ADAMnetworks analyzed the ads and uncovered a "massive 48-hour malvertising blitz" called PasteSwitch. The campaign consisted of 108 distinct ads employing multiple software lures, including infostealers, malware loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications. Hudson Rock identified two specific cryptocurrency clippers, AnimateClipper and ZigClipper, which offer blockchain-based command-and-control fallbacks for attackers.

These clippers utilize Binance Smart Chain (BSC) contracts to dynamically fetch C2 domains, allowing threat actors to easily rotate burned domains, ensuring dynamic resilience.

The attackers employed various lures, targeting HBO Max accounts, developer tools, disk cleaners, and AI-themed ads, including fake OpenAI Codex ads. Of the 108 ads, 46 used an HBO Max lure, directing users to hbomaxx.app or hbomax-macos.com. Another 36 ads attempted to trick users through an OpenAI Codex theme (codex-craft.com). The remaining ads included 15 macOS disk utility lures (apple.clean-disk-guide.com) and 11 other developer tool lures (code-desktop.com).

According to Hudson Rock co-founder and CTO Alon Gal, the campaign highlights the vulnerability of trusted distribution channels to infostealer delivery and the continued heavy use of ClickFix attacks.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Science

More from Monday 14 September →