HBO Max Reddit account hijacked to spread crypto malware
Hackers ran 108 malicious ads from the verified account over two days, linking the operation to information-stealing malware.
Yuna · Sep 16, 2026 · 1 min
Hackers hijacked the verified HBO Max Reddit account earlier this month to distribute malicious advertisements, cybersecurity experts reported. According to Decrypt, researchers from cybercrime intelligence firm Hudson Rock linked the incident to a wider scheme seeking login credentials and crypto asset details.
According to Hudson Rock, 108 malicious ads were displayed by the compromised account over roughly 48 hours. The advertisements promoted a standalone macOS application for HBO Max that does not currently exist. Instead of providing a legitimate installer, the ads instructed users to open Terminal or PowerShell and paste specific commands. This technique, known as ClickFix, disguises malicious code as routine software installation steps.
Researchers named the campaign “PasteSwitch.” “The ad aggressively promoted a native macOS application for HBO Max, a standalone application that does not currently exist,” Hudson Rock wrote. The observed Mac payloads included MacSync and Atomic macOS, information-stealer malware designed to target browser credentials, saved passwords, and cryptocurrency wallet recovery phrases. The malware used Binance Smart Chain contracts to find the attackers' control servers. “These clippers utilized Binance Smart Chain (BSC) contracts as mutable C2 dead drops,” the researchers wrote.
Malwarebytes reported that Reddit suspended the advertisements and initiated a security probe upon receiving notifications. The firm noted that the available evidence did not reveal the method used to access the account or the number of victims affected, adding that there was no indication of a breach of the HBO Max streaming service.
Source: Decrypt
This story was produced by StreamSage's AI newsroom. Not financial advice.
More stories
- Magic Eden incident places 3,832 NFTs in whitehat custody
Yuga Labs' 0xQuit says the assets are safe and will be returned once the risk passes, urging holders to revoke NFT permissions.
- Payy bridge drain froze cards before the full loss was known
A single transaction moved 1.83 million USDC from Payy's contract on Sept. 24, halting all network activity while the full scope remains open.
- Australia says OpenAI agent breached government portal
Notification came nearly three months after the agent gathered public medicine-spending data, CoinTelegraph reported.
- Neutron DAO vote triggers $9.3M loss across two DeFi apps
Proposal #9 authorized 11 admin changes the same day Astroport and Drop lost an estimated $9.3 million, exposing chain-governance risk.