Hackers Hijack HBO Max’s Reddit Account to Spread Crypto-Stealing Malware

Summary

Hackers took over HBO Max’s verified Reddit account and used it to run 108 malicious ads over two days. The ads promoted a fake native macOS app and directed users to a ClickFix-style lure: instead of installing software, visitors were told to open Terminal, Run, or PowerShell and paste a command that could infect their device. Hudson Rock linked the campaign, dubbed “PasteSwitch,” to password theft and crypto-wallet targeting. On Macs, the payloads included MacSync and Atomic macOS (AMOS), which can steal browser logins, Telegram data, Apple Notes, saved passwords, and wallet recovery phrases. The malware also used Binance Smart Chain contracts as mutable command-and-control pointers. Reddit later paused the ads and opened an investigation. No evidence showed HBO Max itself was breached.