A compromised verified Reddit account for HBO Max was used for 48 hours to run a massive PasteSwitch ClickFix malvertising campaign, pushing 108 deceptive ads that led users to fake macOS and Windows installers. The operation delivered MacSync, AMOS, Amatera Stealer, and cryptocurrency clippers through cross-platform lures, deceptive TLS tactics, and smart contract-based C2 infrastructure. #HBOMax #PasteSwitch #ClickFix #MacSync #AMOS #AmateraStealer #AnimateClipper #ZigClipper #Reddit
Keypoints
- The verified u/hbomax Reddit account was compromised and abused for malvertising.
- Attackers pushed 108 ClickFix ads in a 48-hour campaign.
- The lure used a fake HBO Max macOS app and a copied-terminal-command prompt.
- PasteSwitch delivered MacSync, AMOS helper, fake wallet apps, and Amatera Stealer.
- The clipper branch used Binance Smart Chain smart contracts for rotating C2 domains.