Cybercriminals hijacked the official HBO Max Reddit account (u/hbomax) to deploy 108 malicious advertisements over roughly 48 hours. The ads directed users to fake websites mimicking HBO Max and other software tools, using the ClickFix technique to trick victims into manually executing commands that installed infostealers like MacSync and AMOS. The primary target was cryptocurrency wallet seed phrases, the 12 or 24-word sequences that allow anyone to reconstruct and empty a wallet. Security researchers at Hudson Rock and ADAMnetworks linked this operation to a broader campaign dubbed PasteSwitch, active since early 2026, which also uses clipboard hijackers to silently swap wallet addresses with attacker-controlled ones. Reddit eventually suspended the malicious ads after community members flagged them, but the 48-hour window demonstrates how quickly such campaigns can operate before moderation catches up.
Source: Read the original article

