AI · Decrypt
Hackers Hijack HBO Max’s Reddit Account to Spread Crypto-Stealing Malware
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
★ Tier-1 Source
Hackers hijacked streaming service HBO Max’s verified Reddit account earlier this month and used it to run 108 malicious advertisements over two days, cybersecurity experts warn.
Key facts
- Hackers hijacked streaming service HBO Max’s verified Reddit account earlier this month and used it to run 108 malicious advertisements over two days, cybersecurity experts warn
- Observed Mac payloads included MacSync and Atomic macOS (AMOS), information-stealer malware designed to steal sensitive information
- These clippers utilized Binance Smart Chain (BSC) contracts as mutable C2 dead drops,” researchers wrote, explaining that the malware checks Binance Smart Chain contracts for the latest address
- The incident was brought to light by Alex Cutts in the r/cybersecurity subreddit
Summary
HBO Max’s hijacked Reddit account ran 108 malicious ads over roughly 48 hours. Malwarebytes linked the ads to PasteSwitch, an operation targeting Windows and Mac users with information-stealing malware. In its report on Monday, researchers from cybercrime intelligence firm Hudson Rock link the account takeover to a broader operation targeting passwords and cryptocurrency wallet information. “The incident was brought to light by Alex Cutts in the r/cybersecurity subreddit.