Hackers Hijack HBO Max’s Reddit Account to Spread Crypto-Stealing Malware
Hackers briefly took over HBO Max’s verified Reddit account and used it to publish 108 malicious advertisements over about 48 hours, cybersecurity researchers say. The ads funneled users to fake installers and urged them to paste commands into system shells, a tactic tied to a broader operation called PasteSwitch that steals credentials and cryptocurrency data.

Why It Matters
Because the campaign abused a verified brand account to lend credibility to malicious instructions, it increased the risk that ordinary users would execute harmful commands and expose passwords or crypto wallet recovery phrases. The incident illustrates how threat actors combine social engineering and blockchain-based infrastructure to maintain control over stolen-data channels.
Key Facts
- Number of malicious ads: 108
- Duration: Approximately 48 hours
- Compromise reported by: Hudson Rock (cybercrime intelligence firm)
- Initial public report: Alex Cutts on r/cybersecurity
- Malware operation name: PasteSwitch (linked operation)
Security researchers say attackers hijacked HBO Max’s verified Reddit account and used it to run more than a hundred deceptive advertisements over a roughly two-day span. The posts promoted a non-existent native macOS HBO Max application and directed visitors to follow terminal or command-line instructions instead of offering a real installer. That prompt to paste commands into Terminal on macOS or Run/PowerShell on Windows is a known social-engineering method used to execute malware.
Hudson Rock linked the hijacked account activity to a campaign the researchers call PasteSwitch, which adapts its delivery to the visitor’s device and the advertised software. Observed macOS payloads included information-stealing components such as MacSync and Atomic macOS (AMOS). Reported targets for data theft included browser credentials, Telegram content, entries in Apple Notes, saved passwords and cryptocurrency wallet recovery phrases.
The operation also uses blockchain infrastructure to help the malware stay connected to its control servers. Researchers reported that the malware checked Binance Smart Chain contracts for updated command-and-control addresses, allowing attackers to change servers without breaking contact. The broader campaign has been associated with clipboard hijackers as well — tools that replace a copied cryptocurrency address with one controlled by the attacker so transferred funds can be diverted.
Reddit administrators paused the advertisements and opened an investigation after reports surfaced, according to Malwarebytes. The companies involved have not confirmed how the HBO Max Reddit account was compromised, and there is no evidence presented that HBO Max’s streaming service itself was breached. Malwarebytes and Hudson Rock did not provide figures on how many users were infected or how much cryptocurrency may have been lost. The incident follows similar ClickFix-style campaigns and other recent scams that trick Windows and macOS users into running malicious commands.
Keep Reading

OpenAI discloses 6 new cases of ‘misaligned’ AI behavior

Former Waymo CFO jumps to self-driving startup Wayve

I wore Snap’s $2,200 smart glasses
