Security

HBO Max Reddit hijack: the fake Ledger and Exodus apps were built to steal recovery phrases

2 min read

The fake apps behind the hijacked HBO Max Reddit ad campaign were built to steal crypto wallet recovery phrases, security researchers say, making token holders the campaign’s real targets.

Researchers at Hudson Rock traced the incident to an operation they named PasteSwitch: attackers ran 108 malicious ads from the verified u/hbomax account over roughly 48 hours earlier in September, and fake Ledger, Trezor Suite and Exodus applications were among the payloads designed to harvest recovery phrases.

A reader who entered a seed phrase into one of the counterfeit wallet apps handed over full control of their funds, and such transfers cannot be reversed. The malware also included clippers that silently swap a copied wallet address for one controlled by the attacker, so even a careful paste at the wrong moment sends tokens to a thief.

The campaign reached users through a ClickFix prompt, telling visitors to paste a command into Terminal on Mac or PowerShell on Windows instead of downloading an installer. On macOS, researchers observed the MacSync and Atomic macOS (AMOS) info-stealers, which pull browser credentials, saved passwords, Telegram data and other secrets from an infected machine. Windows users were served a separate chain using PowerShell and Amatera Stealer, which could run directly in memory and disguise its traffic as Facebook connections, researchers said.

Hudson Rock also found that some clipper variants used Binance Smart Chain (BSC) contracts as mutable command-and-control dead drops, letting the operators rotate their domains faster than defenders can block them.

The discovery started with a wallet-adjacent detail: Reddit user Alex Cutts noticed the verified u/hbomax account advertising a standalone HBO Max macOS app that does not exist, and posted about it in r/cybersecurity. Hudson Rock published its report naming PasteSwitch on September 14, and Reddit has since paused the ads and opened a security investigation.

The streaming service itself was not breached; reportedly a Reddit account takeover, with no evidence presented that HBO Max’s systems or user data were touched.

Avatar of Theo Okafor

Theo Okafor

Theo Okafor reports on crypto policy and protocol governance for NFT Signals, following legislation through Congress and core development through the upgrade process.