Back Cyberinsider HBO Max Reddit account hijacked in PasteSwitch malware campaign
Researchers at Hudson Rock and Kirk from ADAMnetworks traced the incident to a broader operation they named PasteSwitch, which combines fake software downloads, information-stealing malware, cryptocurrency clippers, and dynamically changing command-and-control infrastructure.
Hudson Rock said analysis of archived activity showed the account published 108 malicious ads within roughly 48 hours. Forty hbomaxx[.]app, while other ads impersonated AI development tools, desktop applications, and macOS disk-cleaning utilities.
The researchers found that PasteSwitch adapted its infection chain according to the victim's operating system and other qualification checks.
On macOS, malicious curl | zsh commands delivered several payloads, including the MacSync information stealer and an AMOS helper that could establish persistence. MacSync targeted browser credentials, Telegram data, Apple Notes, Gecko-based browser profiles, and macOS passwords.
Other macOS lures distributed fake Ledger, Trezor Suite, and Exodus applications written in Swift that attempted to steal 12- or 24-word cryptocurrency recovery phrases.
Windows victims received a separate chain involving mshta and PowerShell. One infection route delivered an MP3/HTA polyglot, created a scheduled task, attempted to disable AMSI, and ultimately loaded the Amatera Stealer directly into memory.
Researchers also observed Amatera connecting to the attacker-controlled IP address 77.91.65[.]13 while presenting .com through TLS SNI and HTTP authority fields, potentially misleading monitoring systems that rely primarily on hostname telemetry.
Another PasteSwitch branch deployed AnimateClipper and ZigClipper, which replace copied cryptocurrency addresses. The malware retrieved changing C2 information from Binance Smart Chain contracts, allowing operators to rotate infrastructure without updating the malware itself.
Users should treat instructions that ask them to paste commands into Terminal, PowerShell, or the Windows Run dialog as highly suspicious, even when they come from verified accounts or convincing branded websites.
Steam client flaw with no fix enables privilege elevation on Windows
CenterPoint Energy confirms data breach after hacker claims 7.49M records
Logitech Options+ flaw lets attackers gain Windows SYSTEM privileges
Nintendo warns of Switch code execution flaw via on-screen QR codes
Malicious Twitch extension exposed OAuth tokens of 30,000 users
Revolut handed customer data to fraudsters using a government email domain
Amar Ćemanović is an experienced editor and trained engineer with a keen eye for detail and a passion for technology. Based in Bosnia, Amar specializes in producing high-quality, engaging content. He holds a Master’s degree in engineering, which helps him maintain a meticulous approach to all editorial work. Amar brings a well-rounded knowledge base, covering everything from tech solutions to privacy tools.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
