PasteSwitch: 108 crypto-theft ads on a hijacked HBO Max Reddit account
Attackers hijacked the official verified HBO Max account on Reddit, u/hbomax , and used it to run 108 distinct malicious advertisements over roughly 48 hours. The ads promoted an "HBO Max for macOS" application that does not exist. Reddit administrators paused the affected ads and opened an internal investigation with their Security and Safety teams to secure the account. One of the 108…
Hackers commandeered the official HBO Max account on Reddit and displayed 108 deceptive advertisements in a short span of about 48 hours. These ads falsely promoted a non-existent HBO Max application for macOS. Reddit's administrators halted the affected ads and initiated an internal investigation with their Security and Safety teams to secure the account.
Among the 108 ads displayed from the hijacked account, one is illustrated in a screenshot shared by Hudson Rock. The research, conducted jointly by Hudson Rock and Kirk of ADAMnetworks, revealed the attackers' tactics.
The attackers employed a method known as ClickFix, which entailed a lure page that presented an installation or verification step and prompted the visitor to copy a command. By pasting this command into Terminal, PowerShell, or the Run box, the visitor unwittingly allowed the command to download and run the payload under their own account. This meant standard operating-system and browser warnings did not appear, as the payload was downloaded and run under the visitor's own credentials.
The operation was dubbed PasteSwitch, reflecting the two-stage process of copy-paste into the terminal. The victim's clipboard and operating system were compromised without any warning. The attackers customized three delivery branches for macOS, Windows, and clipboard hijacking. For macOS, counterfeit Ledger, Trezor Suite, and Exodus applications were distributed, designed to steal 12- and 24-word BIP39 recovery phrases.
Windows received a separate payload path using mshta and PowerShell. The clipboard hijacking, delivered as AnimateClipper and ZigClipper, replaced a copied cryptocurrency address with one controlled by the attacker. These clippers monitored Binance Smart Chain contracts as mutable dead drops, allowing the operator to alter the destination at will.
The researchers documented 36 mainnet changes from a single controller address between March and July 2026. The malicious pointer was hosted on a public blockchain, providing a channel that remained reachable despite ordinary takedowns.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.