For roughly two days, malware ads on Reddit carried the verification badge of HBO Max. Attackers had seized the streaming brand’s official profile, u/hbomax, and turned its standing with the platform into a distribution channel.
The campaign, tracked by Hudson Rock and ADAMnetworks under the name PasteSwitch, ran 108 separate ClickFix ads at macOS and Windows audiences. ClickFix dresses a malicious command as routine upkeep, and the lure list reflected that: 46 pitches for an HBO Max desktop app that does not exist, 36 dressed as OpenAI Codex, plus smaller batches for a fake disk utility and other developer programs.
Traffic was filtered before anything hostile appeared. Browser, screen and device signals decided whether a visitor saw the fake download, a blank page or a pointer to an unrelated legitimate site, a design that blunts automated scanning. Where the bait landed, victims were told to paste a command into a terminal, which pushed curl output through zsh rather than fetching a file first.
Infostealers handled collection. MacSync stockpiled browser credentials, Telegram sessions and Apple Notes in a hidden archive, AMOS Helper posed as a system service, and wallet apps imitating Ledger, Trezor and Exodus harvested 12- and 24-word seed phrases. Windows users met an mshta and PowerShell chain that installed Amatera.
Rounding out the toolkit were clippers that swap copied wallet addresses. Their infrastructure points at smart contracts on the Binance Smart Chain instead of fixed domains, letting the operators refresh staging without registering anything new. Reddit has since suspended the ads and locked the account.
