A verified account gave hackers the perfect cover for a sophisticated ClickFix campaign.
Hackers used HBO Max’s verified account to post 108 malicious ads over 48 hours.
Fake ads led users to lookalike pages that tried to trick them into installing malware.
Researchers say the campaign targeted macOS and Windows users with fake apps, developer tools, and disk cleaners.
A administrator shut down the malicious campaign after it ran for at least two days.
Hackers, after compromising HBO Max’s official account, planted over a hundred fake ads on the site – all to trick users who clicked on them into installing malware,
New research published on Monday and spearheaded by Alon Gal, founder and CTO of Hudson Rock, says the latest HBO Max ClickFix campaign was running amok for at least 2 days before a administrator was able to shut it down.
“For 48 hours, the verified HBO Max account was weaponized to blast 108 malicious ads across the platform, running an evasive cross-platform Clickfix operation we called PasteSwitch,” Gal said in a post the latest find.
And it appears no platform was immune to the campaign, which “spanned macOS stealers, Windows loaders, deceptive TLS tactics, and contract-controlled cryptocurrency clippers.”
It also appears the operation was chock-full of duplicitous tactics, warned Gal and his co-collaborator Kirk from ADAMnetworks, who also published a blog the PasteSwitch operation on Monday.
Infostealing malware – which Gal says has compromised tens of millions of computers to date – is designed to steal user credentials, cookies, documents, browsing history, and a host of other sensitive data.
The September payload was able to collect Chromium and Firefox credentials and cookies, Keychain material, Apple Notes, shell history, SSH material, wallet data, messenger data, password-manager data, and selected files, said Kirk, threat researcher and security analyst at ADAMnetworks.
HBO Max ads hide malware campaign
The researchers said they first became aware of the malicious behavior after some Redditors began interacting with the fake ads – which sent the users to fraudulent sites resembling real HBO Max ads one might encounter on the verified “u/hbomax” account.
Not only that, the bad actor was said to have “squeezed as much value as possible out of the verified account’s status, pivoting quickly when domains were burned."
The research tracked a total of 108 ads across five lure groups during the 48-hour window, promoting items such as fake software, a nonexistent macOS HBO Max app, developer AI tools, and disk cleaners.
More than 40 ads were HBO Max-themed, 36 OpenAI Codex downloads, and the rest were split between a macOS disk utility and desktop developer tools.
What happens when users click?
Instead of simply clicking the download button to install the malware, an instructions page pops up asking the victim to copy an attacker-controlled command and paste and run it on their own computer.
Once they paste and execute that command, PasteSwitch takes over.
This is when the attacker’s infrastructure determines the victim's operating system and which campaign lure they chose, routing them to the appropriate malicious payload.
Another advanced tactic Gal revealed was that PasteSwitch kept its visible lures disposable while preserving operational structure, as the “destination domains, copied commands, and payload infrastructure remained under attacker control.”
Recovered pages and payloads showed separate services for lures, visitor qualification, staging, telemetry, payload delivery, C2, and exfiltration, said Alon Gal, founder and CTO of Hudson RockGal.
The name PasteSwitch was chosen because it describes the exact moment when the delivery system automatically “switches” among the platform, campaign, payload, and monetization branches, Gal said.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
