Mac

Bad Actor Hijacks HBO Max Reddit Account to Spread Mac and Windows Malware

A bad actor hijacked an HBO Max-centric Reddit account to trick Mac and Windows users into installing malware on their machines. The hacker circulated 46 official-looking but fake ads via the u/hbomax account, some of which promoted a malicious desktop app for the streaming service, say security researchers at Hudson Rock and Adam Networks.

A user on Reddit fearlier this month notices that many of the ads led to a fake domain at hbomaxx[.]us that claimed to offer three months of free HBO Max for downloading HBO on macOS. However, when a user clicked the link it triggered a ClickFix-style attack, or a list of seemingly harmless instructions to perform on a Windows PC or Mac.

Hackers often disguise ClickFix attacks to appear to be CAPTCHA or error screens that can pop up on an internet browser, prompting users to execute the instructions to resolve the issue. While computer literate individuals wil likely understand the threat posed by the seemingly benign instructions, casual users can be fooled, unaware that they are downloading and installing malware on their machines.

The researchers said that “by hijacking a verified corporate account, [the attacker] bypassed the initial skepticism many users apply to internet advertisements.”

The macOS malware used in the attack is designed to steal browser passwords, cookies, wallet data, and login credentials from password managers. If a Windows user visited the malicious site, the site served up a ClickFix-style attack targeting that operating system.

The hacker behind the scheme also used the same HBO Max account to distribute dozens of other ads and fake apps, including AI tools Claude and Codex, as well as a supposed macOS system cleaner.

While HBO Max has yet to comment on the situation an admin at Reddit said last week that the social media platform had “paused the affected ads and are looking into what happened with our Security and Safety teams.”

This is not the first ClickFix-style attack we’ve seen this year, as in April,  Jamf Threat Labs, a team of Mac and mobile security experts, identified a new ClickFix-style attack that ditched the typical Terminal-based execution entry point for such attacks.

While the usual approach for ClickFix techniques is to convince users to copy and paste malicious commands into Terminal under the guise of troubleshooting or routine system maintenance, The malware used the macOS Script Editor as the execution point for its final payload, with the campaign being invoked via a URL scheme.

The discovered variant used a browser-triggered workflow to launch Script Editor. Users were shown an Apple-themed webpage claiming to help “reclaim disk space on your Mac,” by following step-by-step instructions that appeared consistent with legitimate system maintenance guidance. When the user clicked the provided “Execute” button, the page triggered the next stage of the workflow.

Chris Hauk

Chris is a Senior Editor at Mactrast. He lives somewhere in the deep Southern part of America, and yes, he has to pump in both sunshine and the Internet.