HBO Max Reddit account used to spread 108 malware and crypto stealing ads in 48 hours

17 hours ago 1



Someone took over the official HBO Max Reddit account and turned it into a malware delivery machine, pumping out 108 malicious advertisements in roughly 48 hours before the campaign was shut down. The ads directed unsuspecting users to fake websites mimicking HBO Max and other software tools. The endgame wasn’t streaming piracy. It was draining crypto wallets. How the attack worked The hijacked account, u/hbomax, carried Reddit’s verified badge, which gave the malicious ads an air of legitimacy that most phishing campaigns can only dream about. Of the 108 ads deployed, 46 were themed around HBO Max specifically, while others posed as downloads for various software tools. The attackers relied on a social-engineering technique called ClickFix. It’s a method that tricks users into manually executing commands in Terminal on Mac, PowerShell on Windows, or the Run dialog box. Victims who followed the instructions unknowingly installed infostealers onto their machines. The fraudulent domains included lookalikes such as hbomaxx[.]us and hbomax-macos[.]com, close enough to the real thing that a casual glance wouldn’t raise alarms. The malware payloads included MacSync and AMOS infostealers,...

Read Entire Article