Static

HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation

First reported by Infostealers ·

The signal ●○○○ Compiled by AI from Infostealers, Reddit and The Register
Why you might care

Malicious ads can now bypass standard protections using verified accounts and social engineering, leading to direct execution of malware.

What happened

In September 2026, a massive malvertising campaign, dubbed PasteSwitch, was uncovered, leveraging a compromised and verified HBO Max Reddit account (u/hbomax). Over 48 hours, this account pushed 108 "ClickFix" advertisements, tricking users into executing malicious terminal commands. The campaign, a joint effort between Hudson Rock and ADAMnetworks, targeted macOS and Windows users with lures for streaming services, AI tools, and system utilities. The PasteSwitch operation is a cross-platform delivery system that dynamically switches between campaigns, payloads, and monetization based on visitor qualifications. It includes macOS stealers like MacSync and fake wallet applications, Windows loaders like InstallFix, and cryptocurrency clippers that use Binance Smart Chain contracts for C2 rotation. Reddit intervened, pausing the ads and launching an investigation.

What it means

The PasteSwitch operation demonstrates a sophisticated evolution in malvertising by integrating multiple attack vectors and platforms under a single, dynamic delivery system. Its reliance on "ClickFix" mechanics, which exploit user trust in verified accounts and corporate branding, allows it to bypass traditional browser-based defenses. The adaptability of PasteSwitch, shifting lures, payloads, and infrastructure while maintaining consistent operational patterns, presents a significant challenge for detection and mitigation efforts. The use of blockchain for C2 rotation further enhances its resilience against takedowns.

This campaign highlights the increasing risk posed by compromised trusted entities, such as official social media accounts, which can be weaponized to distribute advanced threats. The cross-platform nature of PasteSwitch, targeting both macOS and Windows with distinct but coordinated payloads, suggests a mature threat actor capable of widespread impact. Organizations and users should exercise extreme caution with advertisements and downloads, even from seemingly legitimate sources, and be aware of social engineering tactics that prompt command execution.

AI-written summary. May contain errors.

Max