HBO Max's verified Reddit account spent two days advertising malware
For roughly two days last week, ads on Reddit were arriving from HBO Max's verified account. HBO Max had nothing to do with them.
Somebody took over u/hbomax and ran 108 advertisements through it before Reddit's admins noticed and pulled the plug. They pointed at a small stable of lookalike domains registered for the job: 40 sent people to hbomaxx[.]app, 36 to a fake AI and developer tools site called codex-craft[.]com, 15 to apple.clean-disk-guide[.]com, and the remainder to code-desktop[.]com and hbomax-macos[.]com. Researchers at Hudson Rock and ADAMnetworks tied the whole set to a campaign they have named PasteSwitch.
What waits at the far end is the part worth memorising, because it keeps working on people. None of these pages hand you a file to download. They show you an error, or a verification step, or an install instruction, and they tell you to open PowerShell on Windows or Terminal on a Mac and paste in a line of text. That line does everything else. On Windows the payload was Amatera, an infostealer that runs in memory and goes straight for saved browser passwords. On Macs it was MacSync and AMOS, alongside fake crypto wallets fishing for recovery phrases and clipboard hijackers that swap a wallet address in the split second you paste one.
The rule that follows has no exceptions. No legitimate company will ever ask you to copy a command into PowerShell to watch a video, install an app or prove you are human. Not Microsoft, not HBO, not your bank. A verified badge on the account running the ad means nothing, as this week demonstrated. If you think you already did it, Tendvane's safety check lists what has installed itself on the machine and what has been set to start with Windows, which is usually where the answer is sitting.