A Compromised HBO Max Account Became A Malware Storefront
|
In September, a verified HBO Max Reddit account posted 108 malicious ads over 48 hours, split across five lure themes: a fake native HBO Max app, a fake OpenAI Codex tool, a macOS disk utility, developer tools, and a second HBO Max variant. Each led to a ClickFix page: copy this command, open Terminal, paste, run. ADAMnetworks and Hudson Rock followed that copied command and found PasteSwitch, a cross-platform delivery operation spanning encrypted macOS loaders, in-memory Windows execution, fake Ledger and Trezor wallet apps, and smart-contract-controlled clipboard hijackers that rewrite crypto addresses mid-transaction.
|
The same route grammar — lure, gate, copied command, tokenized staging, telemetry, payload — showed up behind fake Claude, Codex, Alfred, and Homebrew pages going back months, and the Windows payload, Amatera, connects directly to its command server's raw IP while presenting facebook.com in the TLS handshake, so network monitoring built around domain names alone never sees the mismatch. Reddit paused the ads once notified, but the infrastructure behind them is built to outlive any one lure. The lesson isn't "don't trust HBO Max" — it's that a verified badge on a platform account says nothing about what happens after someone compromises it, and no legitimate software vendor will ever ask you to paste a command into Terminal to install their app.
|
|
|
|