Researchers reported that criminals hijacked HBO Max’s verified Reddit account and used it to run malicious ads that led people to fake download sites. The sites didn’t provide real installers, instead they tricked users into pasting and running commands in Terminal/PowerShell, causing them to infect their own device. The campaign (dubbed “PasteSwitch”) delivered information-stealing malware and crypto-focused clipboard hijackers.
Key findings
- Attackers hijacked HBO Max’s verified Reddit account and ran 108 malicious ads over ~48 hours.
- Ads promoted fake AI tools, developer software, and macOS utilities, leveraging a trusted brand to reduce suspicion.
- Victims were sent to convincing lookalike sites and instructed to paste/run commands in Terminal (macOS) or Run/PowerShell (Windows), a ClickFix-style workflow.
- The operation was dubbed “PasteSwitch” and appeared to tailor payloads based on device type and lure.
- Observed payloads included AMOS and MacSync infostealers on macOS and the Amatera infostealer on Windows, plus crypto clipboard hijackers.
Who’s being targeted
- Commonly targeted roles: All employees, Developers, IT, Finance (crypto/clipboard risk awareness), Mac users, Windows users.
- Affected industries: Media and entertainment, General consumers, Software/developer communities (via developer-tool lures).
- Attack channels: website.
- Impersonated: HBO Max (lookalike download site), Trusted software/tool download page (from an ad tied to a verified brand account).
Awareness takeaways
- Treat ads and ‘verified’ accounts as untrusted; go to the official site directly for downloads.
- Never run copy‑paste commands from websites/ads (Terminal/PowerShell/Run) unless you fully trust and understand them.
- Recognize ClickFix: ‘CAPTCHA/verify/fix error’ steps that instruct you to paste a command are a common malware delivery trick.
- Use layered protection (web blocking, clipboard protection warnings, and endpoint anti-malware) to stop malicious sites and payloads.
Red flags to watch for
- A software download page provides no installer and instead instructs you to run Terminal commands
- Brand lookalike site reached via an ad rather than the official site
- Site behavior that copies commands to the clipboard and tells you to paste them
- A ‘verification’ or ‘fix’ step that requires running commands on your computer
- Pressure to act quickly or follow step-by-step instructions without explanation
- Download initiated from an ad, even if it appears to be from a verified account
Read the video transcript
Imagine this: you’re on Reddit, you see a legit-looking HBO Max ad offering a “native macOS app” promo download, and it’s from a verified HBO Max account. In the PasteSwitch campaign, criminals hijacked HBO Max’s verified Reddit account and pushed over a hundred ads to fake download sites. Instead of an installer, the site tells you: open Terminal or PowerShell and paste this command to install or fix the app. That’s ClickFix: the page silently copies a command, then walks you through pasting and running it so you infect yourself with infostealers like AMOS, MacSync, or Amatera, plus crypto clipboard hijackers. The only real “install” is malware. Here’s the move: if any download page or ad tells you to open Terminal, PowerShell, or Run and paste a command, stop and close it. Then go to the official site yourself if you still need the app.