HBO Max Reddit Account Compromised in PasteSwitch ClickFix Attack

www.news4hackers.com-hbo-max-reddit-account-compromised-in-pasteswitch-clickfix-attack-hbo-max-reddit-account-compromised-in-pasteswitch-clickfix-attack

A verified HBO Max account was breached and leveraged in a malicious advertising campaign distributing information stealers and cryptocurrency address interceptors as part of a broader operation known as “PasteSwitch,” according to reports from HudsonRock and ADAMnetworks.

Overview of the PasteSwitch Campaign

The campaign was initially identified by a user named Alex Cutts on the r/cybersecurity subreddit, who detected advertisements for a non-existent macOS application linked to the official HBO Max account. HudsonRock and ADAMnetworks’ analysis revealed the compromised account generated 108 advertisements over 48 hours, promoting deceptive content.

Misuse of Trusted Brand Identity

The use of a trusted brand’s verified account significantly increases the likelihood of user engagement, as it implies legitimacy. Ensar Seker, CISO at SOCRadar, highlighted that attackers exploit this trust to enhance social engineering efforts.

“Attackers exploit this trust to enhance social engineering efforts.” – Ensar Seker, CISO at SOCRadar

Technical Details of the Attack

On macOS systems, users who engaged with the malicious ads were redirected to spoofed websites mimicking ClickFix interfaces. Commands copied to the Terminal installed the MacSync infostealer, which harvested macOS passwords, system data, browser credentials, Gecko profiles, cryptocurrency wallet details, Telegram information, Apple Notes, Keychain contents, cloud credentials, and shell history.

Malware Data Exfiltration

Stolen data was compressed into /tmp/osalogging.zip and transmitted to attackers via HTTP PUT requests in 10 MB increments. The PasteSwitch operation also deployed an AMOS helper component, which extracted macOS credentials and application data while installing persistence mechanisms disguised as Apple services.

Cryptocurrency Wallet Interception

Additionally, three counterfeit cryptocurrency wallet applications—impersonating Ledger, Trezor Suite, and Exodus—were deployed to intercept 12- and 24-word BIP39 recovery phrases. Researchers linked the campaign to prior attacks, including Zscaler’s “ClaudeFix” operation in July, which used similar MacSync lures.

Windows-Based Exploitation

On Windows devices, the PasteSwitch ClickFix framework utilized mshta to initiate a PowerShell chain, employing obfuscation techniques such as arithmetic fog, dead loops, opaque predicates, base64 encoding, repeating-key XOR, rolling decoding, and in-memory PE loading. This ultimately delivered the Amatera Stealer, which used TLS SNI spoofing to mask command-and-control (C2) traffic as legitimate connections to a trusted domain.

Cryptocurrency Clippers

The campaign also incorporated cryptocurrency clippers like AnimateClipper and ZigClipper, which replaced clipboard-stored wallet addresses with attacker-controlled ones. These tools shared a 21-address configuration and utilized BNB Smart Chain contracts for dynamic C2 domain management.

Response and Recommendations

Following the discovery, the platform hosting the advertisements suspended the malicious content and initiated an investigation. No official response was received from HBO Max representatives. Seker emphasized the importance of treating corporate social media and advertising accounts as critical infrastructure, advocating for phishing-resistant multi-factor authentication, strict administrative controls, continuous monitoring, and rapid credential revocation.

Conclusion

The breach underscores the evolving tactics of threat actors leveraging trusted brand identities to amplify the effectiveness of malvertising campaigns. The technical complexity of the PasteSwitch operation, including its cross-platform capabilities and advanced obfuscation methods, highlights the need for robust defensive measures against sophisticated cyber threats.

FAQ

What is the PasteSwitch campaign? A malicious advertising operation using a compromised HBO Max account to distribute malware and intercept cryptocurrency data.

How did attackers exploit the HBO Max account? By creating deceptive ads linked to the verified account, increasing user trust and engagement.

What tools were used in the attack? MacSync infostealer, AMOS helper component, Amatera Stealer, and cryptocurrency clippers like AnimateClipper and ZigClipper.

What recommendations were made? Implement phishing-resistant MFA, strict administrative controls, continuous monitoring, and rapid credential revocation for corporate accounts.



About Author

en_USEnglish