Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
ID: b61a7d71-b023-58fa-89e4-15a1872705b7
STIX ID: report--b61a7d71-b023-58fa-89e4-15a1872705b7
Feed Name: Help Net Security
Threat Score
Attackers compromised the verified HBO Max Reddit account to run a large ClickFix social-engineering ad campaign (PasteSwitch) that lured macOS and Windows users into executing commands that installed information-stealing malware, persistence agents, fake wallet apps to harvest seed phrases, and clipboard clippers; the operation used 108 ads across multiple domains, device-aware targeting, in-memory loaders and a blockchain-hosted C2 for resilience.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
