Full Report
Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware
Analysis Summary
# Incident Report: PasteSwitch Malvertising Blitz (HBO Max Reddit Compromise)
## Executive Summary
A verified HBO Max Reddit account was compromised and utilized to distribute over 100 malicious advertisements as part of a "PasteSwitch" malvertising campaign. The attack employed "ClickFix" social engineering techniques to trick macOS and Windows users into executing malicious scripts, leading to the installation of information stealers and cryptocurrency clippers. The incident highlights a trend in leveraging trusted social media identities to bypass user skepticism and traditional security filters.
## Incident Details
- **Discovery Date:** September 6, 2026
- **Incident Date:** September 6–8, 2026 (48-hour blitz)
- **Affected Organization:** Warner Bros. Discovery (HBO Max)
- **Sector:** Entertainment / Media / Technology
- **Geography:** Global (Targeting macOS and Windows users)
## Timeline of Events
### Initial Access
- **Date/Time:** September 6, 2026
- **Vector:** Account Takeover (ATO) / Social Engineering
- **Details:** The verified `u/hbomax` Reddit account was compromised (method unconfirmed, likely credential theft or session hijacking). The attacker immediately began publishing 108 distinct malicious ads.
### Lateral Movement
- **N/A:** The attack focused on external victim acquisition via a trusted third-party platform (Reddit) rather than internal movement within Warner Bros. Discovery networks.
### Data Exfiltration/Impact
- **Details:** Victims who followed the ad instructions had their machines infected with infostealers (designed to exfiltrate credentials and browser data) and cryptocurrency clippers (ZigClipper/AnimateClipper) designed to hijack financial transactions.
### Detection & Response
- **Discovery:** A Reddit user identified the suspicious ads (advertising a non-existent macOS client) and reported them to the `r/cybersecurity` community on Sept 6.
- **Response Actions:** Reddit paused the malicious ads three days later (Sept 9) and initiated a security investigation. Warner Bros. Discovery was notified for comment/remediation.
## Attack Methodology
- **Initial Access:** Compromise of a verified high-profile social media account (Reddit).
- **Persistence:** Payloads included loaders to maintain access; C2 infrastructure utilized blockchain-based fallbacks for resilience.
- **Defense Evasion:** Use of legitimate-looking landing pages; C2 domains hosted via Binance Smart Chain (BSC) contracts to rotate "burned" domains dynamically.
- **Credential Access:** Deployment of Infostealer malware.
- **Lateral Movement:** N/A (Endpoint infection focus).
- **Collection:** Automated gathering of browser cookies, passwords, and crypto-wallet data.
- **Exfiltration:** Standard HTTP/HTTPS exfiltration to attacker-controlled C2s.
- **Impact:** Financial theft through cryptocurrency clippers and identity theft through infostealers.
## Impact Assessment
- **Financial:** Potential loss of user cryptocurrency; costs associated with incident response for HBO Max and Reddit.
- **Data Breach:** Compromise of end-user credentials for those who executed the malicious payloads.
- **Operational:** Disruption of HBO Max’s official social media presence.
- **Reputational:** High; misuse of a "Verified" account diminishes user trust in both the platform (Reddit) and the brand (HBO Max).
## Indicators of Compromise
### Network Indicators
- `hbomaxx[.]us`
- `hbomaxx[.]app`
- `hbomax-macos[.]com`
- `codex-craft[.]com`
- `apple.clean-disk-guide[.]com`
- `code-desktop[.]com`
### Behavioral Indicators
- "ClickFix" prompts: Instructions asking users to copy and paste commands into macOS Terminal or Windows PowerShell.
- Unexpected C2 traffic to Binance Smart Chain (BSC) mainnet for domain resolution.
## Response Actions
- **Containment:** Reddit suspended the malicious advertisements and secured the `u/hbomax` account.
- **Eradication:** Security researchers (Hudson Rock/ADAMnetworks) mapped the infrastructure to flag related malicious domains.
- **Recovery:** Ongoing investigation into the source of the account compromise.
## Lessons Learned
- **Verified Status Fallacy:** Users and automated filters often grant undue trust to "Verified" accounts, which attackers are now aggressively targeting.
- **Social Engineering Evolution:** The "ClickFix" (terminal command) method is highly effective at bypassing browser-based security sandboxes by tricking the user into manual execution.
- **Infrastructure Resilience:** Threat actors are increasingly using decentralized blockchain technology to prevent the permanent takedown of C2 servers.
## Recommendations
- **For Organizations:** Enforce hardware-based Multi-Factor Authentication (MFA) on all corporate social media accounts. Monitor for unauthorized "Official" software clones or landing pages.
- **For Users:** Never copy and paste commands from a website into a terminal or command prompt. Be skeptical of software offerings on platforms that do not match the official developer's distribution site (e.g., macOS apps for services that only offer web/mobile apps).