🔥 Hackers Hijack HBO Maxs Reddit Account to Spread Crypto-Stealing Malware.
In its report on Monday, researchers from cybercrime intelligence firm Hudson Rock link the account takeover to a broader operation targeting passwords and cryptocurrency wallet information. The incident was brought to light by Alex Cutts in the r/cybersecurity subreddit. While browsing the platform, they encountered an official Reddit advertisement authored by the verified u/hbomax account, Hudson Rock wrote. The ad aggressively promoted a native macOS application for HBO Max, a standalone application that does not currently exist. Instead of providing an installer, the site instructed visitors to open Terminal on a Mac, or Run or PowerShell on Windows, and paste a command that could infect their computer.
The technique, known as ClickFix, disguises malicious commands as routine steps for installing software, fixing errors, or proving a visitor is human. The hijacked account gave those instructions the apparent backing of a recognizable company. Researchers dubbed the operation PasteSwitch, warning that its delivery system appears to adapt to the visitors device and the software being advertised. Observed Mac payloads included MacSync and Atomic macOS (AMOS), information-stealer malware designed to steal sensitive information.
❓ What's your take is this the start of a bigger move or just noise? Drop it below.
$BTC $ETH
#SECryptoRegulation #BinanceExchange #AICryptoIntegration
In its report on Monday, researchers from cybercrime intelligence firm Hudson Rock link the account takeover to a broader operation targeting passwords and cryptocurrency wallet information. The incident was brought to light by Alex Cutts in the r/cybersecurity subreddit. While browsing the platform, they encountered an official Reddit advertisement authored by the verified u/hbomax account, Hudson Rock wrote. The ad aggressively promoted a native macOS application for HBO Max, a standalone application that does not currently exist. Instead of providing an installer, the site instructed visitors to open Terminal on a Mac, or Run or PowerShell on Windows, and paste a command that could infect their computer.
The technique, known as ClickFix, disguises malicious commands as routine steps for installing software, fixing errors, or proving a visitor is human. The hijacked account gave those instructions the apparent backing of a recognizable company. Researchers dubbed the operation PasteSwitch, warning that its delivery system appears to adapt to the visitors device and the software being advertised. Observed Mac payloads included MacSync and Atomic macOS (AMOS), information-stealer malware designed to steal sensitive information.
❓ What's your take is this the start of a bigger move or just noise? Drop it below.
$BTC $ETH
#SECryptoRegulation #BinanceExchange #AICryptoIntegration