Verified HBO Max Reddit Account Hijacked to Spread Malware
Cybercriminals used the compromised account to push 108 malicious ads over two days, employing a technique that tricks users into executing malware themselves.
Researchers have discovered that cybercriminals compromised HBO Max's official and verified Reddit account, using it to distribute 108 distinct malicious advertisements over approximately 48 hours. The ads promoted fake downloads for HBO Max and AI tools, as well as developer and Mac utility software.
The campaign, identified by researchers at Hudson Rock, leveraged the credibility of the verified corporate account to lower users' guard. According to the findings, the attackers deployed a technique known as ClickFix, which deceives users into manually executing malicious code. On macOS, this involved tricking users into copying and pasting commands into the Terminal application. For Windows users, similar methods using PowerShell or the Run command were employed.
The ClickFix Technique
ClickFix operates by providing users with instructions that lead them to initiate the attack. This can manifest as a fake CAPTCHA prompt, a notification about a browser problem, or a request to complete an installation. In some instances, a malicious webpage may automatically copy a command to the user's clipboard and then instruct them where to paste it. This process can appear as routine troubleshooting, especially when presented on a professional-looking page originating from a trusted account.
The HBO Max campaign specifically relied on users executing attacker-supplied code through Terminal on Macs. This approach can circumvent some security measures designed to block malicious browser downloads. A key warning sign identified by researchers is when a website requests that users paste unfamiliar commands into system utilities like Terminal or PowerShell.
PasteSwitch Operation
Hudson Rock and researchers from ADAMnetworks linked the HBO Max campaign to a broader operation they've named PasteSwitch. This operation is characterized by the consistent use of the "paste" command by victims, while the delivery system adapts based on the visitor, platform, and specific campaign. This adaptability means that two individuals clicking similar malicious ads might receive different malware payloads.
Within the PasteSwitch operation, researchers observed various malware paths targeting Macs, including MacSync, which could steal browser credentials, Telegram data, Apple Notes, and macOS passwords. An AMOS helper chain was also documented, capable of maintaining access to an infected device.
The operation also involved fake cryptocurrency wallet applications for platforms like Ledger, Trezor Suite, and Exodus. These fraudulent apps were designed to steal cryptocurrency wallet recovery phrases. Additionally, the PasteSwitch operation was linked to cryptocurrency clipboard hijackers, such as AnimateClipper and ZigClipper. These tools monitor the clipboard and replace legitimate cryptocurrency addresses with the attacker's own when a user attempts to paste them, potentially rerouting funds.
Reddit's Confirmation and Response
Reddit confirmed that an HBO Max account authorized to run advertisements on its platform was compromised. "We recently learned that an HBO Max account authorized to run advertisements on Reddit was compromised and used to run ads containing malicious links," a Reddit spokesperson stated. "After learning of the issue, we locked the account, removed the ads and began working with HBO Max to strengthen its account security." Reddit reported that no other advertising accounts were identified as being impacted.
Protecting Against Malicious Ads
Experts advise caution with online advertisements, even those appearing under verified accounts or from recognized brands. A common recommendation is to independently navigate to a company's official website rather than clicking on an advertisement, especially when seeking software downloads. For applications, using official app stores is also advised.
Key recommendations for users to protect themselves include:
- Treating all ads with caution, regardless of the account's verification status.
- Never pasting commands into system utilities without fully understanding their purpose.
- Obtaining software exclusively from official websites or app stores.
- Paying attention to browser or security software warnings about clipboard activity.
- Keeping device operating systems and browsers updated.
- Using robust antivirus software with real-time protection.
- Disconnecting from the internet and performing a security scan if a suspicious command has already been run.
- Enabling multifactor authentication for sensitive accounts.
macOS has introduced warnings for pasted text that resembles potentially harmful commands, but users are still urged to exercise judgment, as attackers continuously adapt their methods.