HBO Max Reddit account compromised to serve ClickFix attacks

https://image.theregister.com/5296419.jpg?imageId=5296419&x=0&y=19.17&cropw=100&croph=71.67&panox=0&panoy=19.17&panow=100&panoh=71.67&width=1200&height=683

Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware

Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware.

A Reddit user uncovered the infostealer ads on September 6, noting that the ad showed u/hbomax as the author — this is the verified HBO Max account — and advertised a macOS app for HBO Max. The streaming service does not offer a native client for the Mac.

Anyone who clicked on the malicious ad would then be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button.

Clicking the button produced instructions telling the user to copy and paste a command into Terminal on macOS.

The Reddit security sleuth described that as “the classic infostealer/clickfix paste this command to download,” noting...

Copyright of this story solely belongs to www.theregister.com. To see the full text click HERE

Read more