Hackers Hijack HBO Max Reddit Account to Push 108 Malicious Ads

The macOS payloads included counterfeit Ledger, Trezor Suite and Exodus applications designed to harvest victims’ 12- and 24-word BIP39 cryptocurrency recovery phrases.
The campaign also used clipboard hijackers called AnimateClipper and ZigClipper, which replaced copied cryptocurrency addresses with attacker-controlled addresses before transactions were sent.
Researchers found that the clippers obtained their command-and-control locations from Binance Smart Chain contracts used as mutable dead drops; one controller address recorded 36 destination changes between March and July 2026, making the infrastructure harder to disable through ordinary hosting takedowns.
The campaign was initially exposed when a Reddit user noticed an advertisement from the verified HBO Max account promoting a native macOS HBO Max application, which does not exist; clicking the download button led to a convincing landing page that displayed the ClickFix terminal-command prompt instead of starting a normal file download.
Hackers took over HBO Max's verified Reddit account and posted 108 malicious ads over two days, targeting Windows and macOS users with fake applications and malware SecurityWeek. The fake ads promoted a nonexistent macOS HBO Max app, bogus AI tools, and cryptocurrency software designed to steal wallet recovery phrases and intercept transactions Cybernews.
The attack used a technique called ClickFix, which tricks victims into copying commands into system tools like PowerShell or Terminal, allowing malware to run without being downloaded normally HITechHub. Researchers linked the campaign to PasteSwitch, a broader malware operation distributing information stealers and fake wallet apps uk.headtopics.com.
When users clicked the fake HBO Max download ad, they reached a landing page that looked legitimate but displayed a terminal command prompt instead SecurityWeek. The ClickFix technique exploits trust in system tools—victims copy a command into PowerShell, Terminal, or Windows Run, and malware executes instantly without a traditional file download Archynetys. This bypasses many antivirus programs that watch for suspicious downloads.
The malware payloads included counterfeit versions of Ledger, Trezor Suite, and Exodus—major cryptocurrency wallet apps Cybernews. These fakes were built to harvest victims' 12- and 24-word BIP39 recovery phrases, which are master keys that unlock entire cryptocurrency wallets. Once stolen, attackers can drain funds without the owner's knowledge uk.headtopics.com.
Beyond theft, the campaign deployed clipboard hijackers called AnimateClipper and ZigClipper SecurityWeek. These tools replace cryptocurrency addresses users copy before sending transactions, swapping them with attacker-controlled addresses. Victims paste what they think is their intended recipient's address but unknowingly send funds to hackers instead Cybernews.
Researchers found the clipboard hijackers retrieved their instructions from smart contracts on Binance Smart Chain, which served as mutable dead drops SecurityWeek. One attacker controller address changed locations 36 times between March and July 2026, making traditional takedowns ineffective. By hiding command infrastructure on the blockchain, attackers made their malware harder to shut down than usual server-based operations HITechHub.
Publishers
16
Articles
9
Reach
25