adamnet.works HBO Max Ads Compromise Expose PasteSwitch ClickFix Operation
Article Content
- •108 malicious ads were published from a compromised HBO Max account over 48 hours.
- •The PasteSwitch operation targets both macOS and Windows users through deceptive tactics.
- •Joint research confirmed the operation's extensive infrastructure and its exploitation of user trust.
In September 2026, a compromised HBO Max account published 108 malicious ads over 48 hours, targeting macOS and Windows users. The ads directed users to fake software pages that executed attacker commands in the Terminal, leading to the PasteSwitch ClickFix operation. This cross-platform campaign utilized deceptive TLS tactics and contract-controlled cryptocurrency clippers. The PasteSwitch operation involved multiple components, including MacSync, AMOS, and fake wallet applications, which aimed to exfiltrate sensitive user data. The incident was confirmed through joint research by Hudson Rock and ADAMnetworks, revealing a broader malvertising blitz that exploited the trust associated with verified accounts. Administrators have paused the ads and initiated a security investigation. The attack method successfully bypassed standard browser protections by tricking users into executing malicious commands themselves.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Mentalpositive, ClickFix and HBO Max in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Russia's AI-Driven Cyber Espionage Targets Ukraine and Europe A Russian-linked hacking group, identified as GTG-20006, has utilized Anthropic's Claude AI to automate cyber espionage against over 20 organizations, primarily in Ukraine and Europe. The group targeted Ukrainian government officials, military personnel, and drone manufacturers through sophisticated phishing and…
Rapid7 Reports Surge in Vulnerability Exploitation Outpacing Patching Efforts Rapid7's Q2 2026 Threat Landscape Report reveals a significant increase in vulnerability disclosures, with high and critical vulnerabilities doubling to 8,539. Newly exploited vulnerabilities surged by 40%, with 62% requiring no user interaction to exploit. The report highlights that attackers are leveraging…