Crypto Prices

HBO Max Reddit Account Compromised in Malware Scheme Targeting Cryptocurrency Users

16 hours ago
1 min read
7 views

HBO Max Reddit Account Hacked

Earlier this month, HBO Max’s officially verified Reddit account fell victim to hackers who exploited it to circulate 108 deceptive advertisements within a span of just two days, according to cybersecurity analysts from Hudson Rock. This breach is emblematic of a wider operation targeting sensitive data, including passwords and cryptocurrency wallet details.

Discovery of the Breach

The discovery of the compromised account was first made public by Reddit user Alex Cutts in the r/cybersecurity forum. While browsing, Cutts stumbled upon an official advertisement attributed to the HBO Max account, which pushed a non-existent macOS app. The ad did not merely offer an installer; rather, it instructed users to open Terminal on Mac or use Run or PowerShell on Windows and execute a command that was likely to infect their systems.

ClickFix Methodology

This method, termed ClickFix, cleverly disguises harmful commands as routine installation steps or system fixes, thereby leveraging the credibility of a well-known brand to deceive users. The malware operation, identified as PasteSwitch, demonstrated a level of adaptability, adjusting its strategies based on the visitor’s device and the software it claimed to endorse.

Payloads and Threats

Among the harmful payloads aimed at Mac users were MacSync and Atomic macOS (AMOS), both designed to extract sensitive information, such as browser credentials, Telegram messages, Apple Notes, saved passwords, and cryptocurrency recovery phrases. According to the report, the attackers utilized Binance Smart Chain (BSC) contracts as dynamic command and control (C2) servers, allowing them to update their server addresses without altering the malware’s base functionality. This means that the malicious software can continuously locate and communicate with the hackers, ensuring their operation remains active.

Clipboard Hijacking and Recovery Phrases

Additionally, this incursion has been linked to clipboard hijackers in the cryptocurrency space, which can replace a copied wallet address with one controlled by the attackers. If an unsuspecting user pastes this altered address, they may inadvertently send funds to the hacker instead of their intended recipient. Compromised recovery phrases compound the threat by potentially granting attackers unauthorized access to the victims’ wallets.

Response and Investigation

Following these revelations, Reddit’s administrative team promptly halted the troubling advertisements and initiated a security investigation. However, the specific methods the hackers used to compromise the account remain unclear, as does the number of individuals affected by this incident. It is noteworthy that the report did not indicate any breach of the HBO Max streaming service itself.

Broader Implications

The ClickFix technique has gained notoriety in recent campaigns targeting cryptocurrency users, including an operation discovered in August involving approximately 2,000 hacked WordPress sites that utilized fake verification prompts to siphon off wallet information. Microsoft researchers have also identified another scheme that exploited fake CAPTCHAs to mislead Windows users into executing harmful commands, showcasing the variety of tactics employed by cybercriminals targeting online users and their financial assets.

Popular