Hackers compromised HBO Max’s verified Reddit account and used it to distribute more than 100 malicious advertisements designed to trick users into installing information-stealing malware.

 

 

Researchers at HudsonRock and ADAMnetworks investigating the campaign found that attackers launched 108 ads from the official u/hbomax account during a period of roughly 48 hours. The use of an established and verified account gave the advertisements an appearance of legitimacy that could make users less suspicious.

One of the main lures promoted what appeared to be an HBO Max application for macOS. Users who followed the advertisement were taken to websites designed to resemble legitimate download or installation pages.

Instead of providing genuine software, the sites used a social engineering technique known as ClickFix.

ClickFix attacks generally instruct users to copy a command and paste it into a terminal or another system tool. Following those instructions causes the victim to execute malicious code themselves, allowing attackers to install malware while making the activity appear to have been initiated by the user.

The HBO Max campaign targeted both macOS and Windows systems. Researchers connected the incident to a broader malicious advertising operation known as PasteSwitch, which uses similar fake software, installation, and verification pages to distribute malware.

The campaign was not limited to fake HBO Max software. Investigators found related infrastructure impersonating other applications and tools, suggesting that the compromised Reddit account was one distribution channel within a considerably larger operation.

Information-stealing malware is particularly dangerous because it can collect credentials and other sensitive information stored on infected computers. Depending on the malware involved, stolen data can potentially provide attackers with further access to online accounts and services.

The incident attracted attention after Reddit users noticed suspicious advertisements apparently published by the verified HBO Max account. One user reported an advertisement for a macOS application and discovered that the linked website attempted to convince visitors to run a command on their computers.

Reddit subsequently paused the affected advertisements and said its Security and Safety teams were investigating what had happened. The malicious campaign had been active for at least two days before being stopped.

The incident demonstrates how compromised social media accounts can be valuable to malware distributors. Rather than relying entirely on obviously suspicious profiles, attackers can abuse the reputation of an established brand and combine it with paid advertising to place malicious content directly in front of users.

The investigation has linked the advertisements to the wider PasteSwitch operation, but details about how the HBO Max Reddit account was initially compromised have not been publicly established.

Leave a Reply