An elaborate malware campaign has exploited the trusted identity of HBO Max to target Mac and Windows users with fake ads on Reddit. Cybersecurity researchers say attackers compromised the verified HBO Max Reddit account and distributed malicious ads to trick users into going to fake websites that were made to look like legitimate sites to trick them into executing harmful commands on their own devices.
And the campaign was particularly disturbing since it didn't depend on the usual malicious download. Instead, attackers used a social-engineering method called ClickFix to trick users into copying and pasting commands into their computer’s Terminal or Command Prompt. By forcing users to execute the commands themselves, attackers may bypass some of the security protections that normally check suspicious downloads.
According to Hudson Rock and ADAMnetworks, the compromised verified HBO Max Reddit account was used to run 108 malicious advertisements over about 48 hours. Researchers described it as PasteSwitch. It promoted some fake software products such as an HBO Max application on macOS that does not exist.
A verified corporate account was one of the main points of deception. Users tend to be much more likely to trust advertisements that are marketed as being from a well-known entertainment company, especially when they include a verification sign. The attackers took advantage of that credibility to lower the suspicion associated with new software ads, the researchers said.
How does the ClickFix attack work?
The campaign starts when a user sees one of the malicious advertisements. Clicking the advertisement would send the user to a fake website that looks like an authentic HBO Max page or another legitimate software service.
Instead of providing a normal software download, the website provides instructions to invite the user to perform something on the computer. In typical ClickFix campaigns, this can be a fake verification, CAPTCHA, or installation process that tells the user to copy a command and paste it into Terminal on macOS or Command Prompt/PowerShell on Windows.
The dangerous part is the user’s own interaction. Once the malicious command is executed, it can download and launch additional malware without the victim necessarily realizing what has happened. ClickFix is becoming an increasingly important social-engineering technique because it turns the victim into an active participant in the infection process.
Windows users are targeted differently from Mac users.
Researchers found that the campaign was designed to identify the victim's operating system and deliver different payloads accordingly.
The infrastructure on macOS was associated with information-stealing malware that was targeting sensitive data, including passwords and session information. Researchers looked for fake cryptocurrency-related applications and other lures targeting users of digital assets.
Windows users were targeted through a different delivery chain involving mshta and PowerShell. The investigation identified the Amatera Stealer, an information-stealing malware family, as the payload. The researchers also observed techniques designed to make the malicious activity harder for conventional security monitoring to detect.
The attackers also used rapidly changing infrastructure. If malicious domains were identified or blocked, the campaign could move to other domains and continue with the same underlying malware operation.
Why is the attack important?
It showed that cybercriminals are now seeking more and more trusted online identities rather than just “suspicious” websites or messages. A compromised brand account can also give the fake advertisement an appearance of legitimacy before the victim even gets to the fake website.
The campaign also highlights the growing threat posed by social engineering. Security advice is usually based on avoiding unknown downloads, suspicious attachments, and untrusted websites. ClickFix attacks try to subvert that advice by making the malicious action look like a normal troubleshooting or verification step.
Reddit has also paused the ads that are in question and secured the compromised account after the campaign was discovered.
The lesson for the user is simple: never paste commands into Terminal, Command Prompt, or PowerShell because a website tells you to do so. Legitimate streaming services and normal website verification should not require users to learn to run unknown system commands if their websites say you should.
HBO Max users who saw suspicious ads in the campaign should avoid visiting the linked websites and downloading purported HBO Max applications from unofficial sources. Anyone who thinks they might have executed a suspicious command should disconnect the affected device from sensitive accounts, run reputable security checks, and change important passwords from a clean device.
The HBO Max ClickFix campaign is another reminder that even trusted brands, verified social media accounts, and seemingly legitimate advertisements can be abused by cybercriminals. As hackers continue to marry malvertising with sophisticated social engineering, users will have to look at what websites they visit and what the websites tell them to do.