Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Hackers have used a trusted Reddit identity to turn advertisements into a malware delivery channel. A compromised, verified HBO Max account, u/hbomax, published 108 malicious ClickFix ads over 48 hours, sending people toward fake software pages.

The campaign did not rely on a software vulnerability. It relied on persuasion: a polished page claimed to offer a native HBO Max app for macOS, then told visitors to copy a command into Terminal. That handed the final execution step to the victim.

HudsonRock researchers, working with independent researcher Kirk from ADAMnetworks, identified the activity as part of a wider cross-platform operation they call PasteSwitch.

The operation linked fake streaming ads with lures for AI tools, developer utilities and disk-cleaning software. The potential impact goes well beyond an unwanted ad.

HudsonRock said in a report shared with Cyber Security News (CSN) that PasteSwitch can deliver credential stealers, Windows loaders and cryptocurrency-address clippers, risking browser data, saved passwords and digital assets.

The initial report (Source - Hudson Rock)
The initial report (Source – Hudson Rock)

It also gives attackers a reusable framework that can swap brands, lures and payloads while retaining the same underlying core delivery methods. Reddit paused the ads and began an investigation, but a verified account is not proof that a download is safe.

Hackers Hijack HBO Max Reddit Account

The suspicious advertising was first reported after a Reddit user encountered an official-looking ad from u/hbomax.

It promoted a standalone macOS application that does not exist. The linked page copied HBO Max branding before presenting its trap.

ClickFix works by replacing a normal install with a manual action. After a visitor pressed Download, the page displayed an overlay that asked them to copy and paste a command. As recent ClickFix malware attacks demonstrate, this approach makes users run attacker code.

The fraudulent landing page hosted at hbomaxx[.]us (Source - HudsonRock)
The fraudulent landing page hosted at hbomaxx[.]us (Source – HudsonRock)

The operators moved quickly as domains were detected or blocked. Ads included 40 streaming-themed placements using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com.

The compromised account gave the actors a trusted advertising identity for two days. Convincing branding can lower caution around ads.

PasteSwitch Expands Across Platforms

The researchers found a delivery system that changes its path depending on the visitor and campaign. On macOS, the pasted command can use curl and zsh to fetch MacSync, AMOS-related helpers or fake wallet apps.

They can collect credentials, Telegram data, Apple Notes and macOS passwords; fake wallets seek recovery phrases. Windows visitors can receive a separate InstallFix route that uses mshta and PowerShell.

A disguised MP3/HTA file can create a scheduled task, launch 32-bit PowerShell and disable the Antimalware Scan Interface before subsequent code runs.

Amatera can then load into memory, evading conventional file-based checks. The report also described deceptive TLS traffic that connected to an attacker-controlled IP while presenting facebook.com as its visible server name, potentially misleading simple network logs.

The operation’s clipper branch adds another risk. AnimateClipper and ZigClipper watch the clipboard and replace copied cryptocurrency addresses with an attacker’s address.

The archived account activity using PullPush (Source - HudsonRock)
The archived account activity using PullPush (Source – HudsonRock)

Their controllers can retrieve a current command-and-control domain from Binance Smart Chain contracts, letting actors rotate infrastructure.

Defenders should block the listed infrastructure, inspect alerts involving copied commands and investigate unexpected Terminal, Run-dialog, mshta or PowerShell activity.

Never paste commands from ads, pop-ups or web pages. Mac-focused ClickFix delivery chains show why verification and installer commands deserve caution.

Organizations should also review whether staff saw the ads or visited the associated sites, reset exposed credentials if exposure is suspected and monitor for unusual browser-data collection.

Network teams can correlate direct IP connections with unusual SNI, DNS and certificate behavior. Earlier reporting on blockchain C2 malware campaigns also illustrates why blockchain-based control channels need attention during an investigation.

The HBO Max incident is a reminder that malvertising can borrow the reputation of a legitimate account, then turn a routine click into an infection. Treat copy-and-paste install prompts as warnings and validate software through official channels.

Indicators of Compromise (IoCs):-

Type Indicator Description
IP address 45.94.47[.]204:80 AMOS helper enrollment, task polling and acknowledgement server
IP address 77.91.65[.]13:443 Amatera direct-to-IP TLS command-and-control server using facebook[.]com SNI
IP address 165.22.199[.]85 September macOS telemetry and /contact data exfiltration
IP address 164.90.161[.]147:80 September macOS post-execution HTTP contact
IP address 92.246.136[.]14 AMOS helper fallback /contact exfiltration
IP address 62.60.226[.]69 Shared Nova and macOS-tool cluster provisioning infrastructure
IP address 176.53.159[.]66 Shared delivery infrastructure associated with TLS and Windows executable activity
IP address 172.236.51[.]169 Origin observed for storageprofiler[.]com gated lure
IP address 138.124.93[.]32 AMOS helper /contact exfiltration
IP address 168.100.9[.]122 AMOS helper /contact exfiltration
IP address 199.217.98[.]33 AMOS helper /contact exfiltration
IP address 38.244.158[.]103 AMOS helper /contact exfiltration
IP address 38.244.158[.]56 AMOS helper /contact exfiltration
Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[.]com Copied-command lure domains
Domain flutelikelurkerunsinewy[.]com; camaligsalvatrefoils[.]com Click-tracking domains
Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery domains
Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry and delivery domains
Domain houstongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains
Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains
Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains
Domain desktop-version[.]com; oakenfjrod[.]ru Windows staging domains
Domain sic180[.]com; habar55[.]namebright[.]bike SIC Windows-route domains
Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; codex-craft[.]com; code-desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-linked lure domains
Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning-neighborhood domains
Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com; hindustanagency[.]com Teardown and delivery-neighborhood domains
Domain euquiz[.]space Address-reuse domain
Domain lb[.]propertyfind[.]cc Smart-contract-resolved command-and-control domain
Domain br[.]hugo-lapp[.]co; carlessclapped[.]com; cf[.]hugo-mapp[.]co; cw[.]hugo-lapp[.]lat; dau[.]hugo-mapp[.]co; dmt[.]unguidedfreewill[.]co; doh[.]hugo-mapp[.]co; ed[.]hugo-lapp[.]lat; en[.]hugo-mapp[.]co; esp[.]hugo-mapp[.]co; fcp[.]unguidedfreewill[.]co; fd-api-irc[.]velqo7[.]co; fd-api-irf[.]velqo7[.]co C2 history decoded from AnimateClipper and ZigClipper smart-contract transactions
URL path / artifact /dynamic?txd=; /tmp/osalogging.zip; .com.apple.accountsd; /api/join/; /api/tasks/<bot-id> MacSync and AMOS helper staging, persistence, enrollment and tasking indicators
Smart contract 0x6936edc505501EBB2F202C985a021a06f1c10C9E AnimateClipper Binance Smart Chain contract
Smart contract 0x7CC3cFC1Ac007B8c6566fD2C7419b15a75473468 ZigClipper Binance Smart Chain contract
Cryptocurrency wallet 0x3a35b409af86e79e8945d6a7ffb1dc59b8dbdf46 Attacker controller address associated with contract updates
Smart-contract method 0x3bc5de30; 0x70a08231; 0x47064d6a Selectors for getData(), balanceOf() and setData()
SHA-256 eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009 September macOS artifact
SHA-256 d4150c1c97f047c6edb14767bf1efa8f9e37d63b124f38f27da4ef52d570aac2 AccountsHelper artifact
SHA-256 f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7; a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287e6a411 Metadata artifacts
SHA-256 93d986f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae; e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c Arkypc loader and helper
SHA-256 f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e; 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4; ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb Fake Ledger, Trezor and Exodus application artifacts
SHA-256 5e8ad983129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad; 480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5; 3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92541a24 InstallFix MP3/HTA, InstallFix /cl and recovered InstallFix artifacts
SHA-256 ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb Recovered x86 artifact and Amatera PE
SHA-256 6759c72365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7; 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 SIC MP3/HTA payload and Talos clipper artifact
SHA-256 06a3d3bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b; d1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c; ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540; 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505; 249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938; 9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e849cd96 Houston, Pressureulcerlawyer, Lalandscapelighting, Aidevmaster, Pinescope11 and Dogtrainers MacSync shell stages, plus Trekmesh15 AMOS helper shell stage
Cryptocurrency wallet 0xA1E50DaF64fb2B342A64d848E396700962acC2d0; 1PbWWqgKDBDorh525uecKaGZD21FGSoCeR; 31kwGkJP9xM26cnQJLpe1CH6pjSt4DEDz2; 32Epo1K92Xzo6Hayq1Fmkj21x4fUk7JZT7; bc1qcg5sx6a6evx5ls4gj6nh8d0jtamh89n2y473dr; bc1pqn73hlel3mmnza0kfl2alwkkgkapeeknufgtysll8fs2z4umdf0qpvus9q; ltc1qk437ykzdxms9k9wh5vhd7aalsv0tfx6r39rrtv; LV9AYZKQEg891crnof7PFK6u77noVM4Y45; MG1FerSxboiwjhvU2cv4n34pXz5FpC88p4; TNf4nzc6x6fZrBMLMaZZGV1SbCjShDqbaQ; r9yMnTm4NSzvG9rrwjM2ec8xZgh1cafXH8; cosmos1k5xu6njlc90r92gdwvtfjh826jduw7ptmry0q8; UQDvDUxFShoWWbHougyHjr0tFz3E38fX8e0bnTUpya-P0mXW; DH9W9S6mSSBsGeiSstgsGdiREZupQbZf9C AnimateClipper and ZigClipper cryptocurrency address-replacement targets
Cryptocurrency wallet addr1q96640zpnccyktlmjqnzqnypwugva9g9dcuk0f5jt9mjz3xh54zest5mg6mqh9d; stake1u8t623vc96d5ddstjk46q2l59jeg38y3d0g2asqzf2n2ntqjv72k8; X-avax1h9qxee0820ezfkgeeuc02gkc0c77xrypx8z6g2; bitcoincash:qqkmn6qq7k0wpa5x7qxze5c4lkcsjkrsvsy2ecll6y; bnb1jvds8pg6zkxd2s7dl8klr0dye5avlfv8mm25jm; bc1qkg288agwvjs9cnmhz2q2f4p0x6nttwwngue7v0; 1EZk7eLw52dErMygLvfKQJJ6KVWk8gPgvE; 3K4JfWQv1ye2DAmgfcnMUBJSLnux7Lpf2X; bc1p6nwq0zs0dhcf5zgsfhjrr93enggkzmvqpwxld85egv7zamrcktqsdxmjvt; cosmos13ppe5rlcmlsgp4mlzxuma4nypcgh22upkjgf0k; DNZCS9qtuibaMtgVTf9Ttr7SuXaXRCMsDN; 13ky7J5igHNFeYogpkPh88CzwFNNh46DseTT64uqqvumgeJy Wuess clipper cryptocurrency address-replacement targets

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads appeared first on Cyber Security News.