Cybercriminals hijacked HBO Max’s verified Reddit account and used it to publish 108 malicious ads in about 48 hours, according to researchers. Anyone who followed those ads and pasted a suggested command into Terminal, PowerShell or Windows Run may have exposed passwords, browser data or cryptocurrency wallets.
Reddit paused the ads and opened a security investigation after receiving reports.
ADAMnetworks named the operation behind these ads “PasteSwitch” and found that its next stage appeared to change according to the visitor’s device and the lure shown.
Windows visitors could receive the memory-based Amatera information stealer. The campaign was also linked to clipboard hijackers that replace a copied cryptocurrency wallet address with one controlled by an attacker.
Trusted account, unsafe ads
Malwarebytes Labs reported that the ads promoted fake AI tools, developer software and Mac utilities through HBO Max’s corporate account. Some led to convincing HBO lookalike sites offering a supposed native HBO Max app for macOS or another promotional download.Reddit paused the ads and opened a security investigation after receiving reports.
The download was really a ClickFix trap
Instead of supplying an installer, the sites told visitors to paste a command into macOS Terminal, or into the Run dialog or PowerShell on Windows. This method is known as ClickFix: a page presents malicious commands as a normal installation, CAPTCHA or troubleshooting step, sometimes copying the command to the clipboard first.ADAMnetworks named the operation behind these ads “PasteSwitch” and found that its next stage appeared to change according to the visitor’s device and the lure shown.
What could be stolen
Observed Mac payloads included the MacSync and AMOS information stealers. They target browser credentials and profiles, Telegram data, Apple Notes, saved passwords and cryptocurrency wallet recovery phrases.Windows visitors could receive the memory-based Amatera information stealer. The campaign was also linked to clipboard hijackers that replace a copied cryptocurrency wallet address with one controlled by an attacker.
Steps to avoid this attack
- Open a company’s official website yourself rather than installing software through a social media ad.
- Do not paste commands from ads, websites, emails or messages unless you trust the source and understand exactly what they do.
- Ignore countdowns and other pressure tactics. Verify unusual instructions through official documentation or the company’s support team.
- Keep real-time anti-malware and web protection enabled and up to date. Malwarebytes identifies ember-bridge.com as part of the PasteSwitch infrastructure.