Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-15 ยท updated: 2026-09-15 ยท tags: [incident, retail, macos] ยท confidence: high ยท severity: critical ยท affected_sectors: [retail] ยท au_impact: true

The verified Reddit account belonging to HBO Max was hijacked and used to push 108 distinct malicious advertisements over roughly 48 hours, in a malvertising operation that Hudson Rock and ADAMnetworks, working jointly, have named PasteSwitch and traced across macOS and Windows payload branches. The campaign was first noticed by a Reddit user who saw an advertisement authored by the verified u/hbomax account promoting a native macOS HBO Max application that does not exist; the advertisement led to a convincing clone of the streaming service's site whose download button produced not an installer but a ClickFix prompt instructing the visitor to paste a command into Terminal. One macOS command seen by BleepingComputer used Base64 to obscure a curl | zsh fetch from an attacker domain. The account's reach was stretched across unrelated lures: 40 advertisements pointed at an HBO Max clone domain, 36 at a site promoting fake AI and developer tools, 15 at a supposed macOS disk-cleaner guide, 11 at another AI/developer lure and six at a second HBO Max clone. The macOS payloads include MacSync, which exfiltrates browser credentials, Firefox profiles, Telegram data, Apple Notes and macOS passwords, and an "AMOS helper" chain that persists under a directory disguised as an Apple path and enrols the victim with attacker-controlled tasking endpoints, alongside fake Ledger, Trezor Suite and Exodus wallet applications built to steal 12- and 24-word recovery phrases. On Windows the campaign delivered an MP3/HTA polyglot through mshta that created a scheduled task, launched 32-bit PowerShell and disabled Microsoft's Antimalware Scan Interface before loading the Amatera stealer directly into memory, and the malware presented Facebook's hostname in its TLS SNI field while connecting to an attacker IP, so standard network telemetry logs a connection to a legitimate service. Cryptocurrency clippers in the same operation use Binance Smart Chain contracts as a mutable command-and-control dead drop, with 36 mainnet changes observed between March and July. Reddit administrators paused the advertisements and referred the incident to internal security teams; it remains unclear how the account was accessed or whether other Warner Bros. Discovery assets were affected.

Attribute Detail
Sector Retail & Entertainment & Sport
Date 2026-09-15
Source Hudson Rock
Reliability Tier 1