Ready to play
Ready to play
Cybercriminals hijacked HBO Max's verified Reddit account to run a campaign that distributed over 100 malicious ads in approximately 48 hours. These ads promoted fake HBO Max downloads and software utilities, leveraging the account's credibility to deceive users into executing malware through prompts requiring commands to be pasted into Terminal or PowerShell. The attack utilized the ClickFix technique, which tricks users into manually running malicious code, bypassing traditional security measures. The campaign was linked to a broader operation called PasteSwitch, which used adaptable malware delivery paths and targeted multiple platforms, including Mac and Windows, to steal credentials, cryptocurrency wallets, and inject malware. Reddit confirmed the account compromise and took steps to secure it.
Notice: This Is an AI-Generated Summary
Comments (0)