Home / Technology / Fake HBO Max Ads Infect PCs with Malware

Fake HBO Max Ads Infect PCs with Malware

Summary

  • Hacker used a hijacked Reddit account to distribute fake ads.
  • Malware targeted both Windows PCs and Macs with fake apps.
  • Attack involved a ClickFix-style scam to trick users.

A malicious actor compromised a Reddit account associated with HBO Max to distribute deceptive advertisements. This account was utilized to circulate 46 fake ads, many promoting a fraudulent desktop app for the streaming service. Researchers identified a fake domain, hbomaxx[.]us, which offered free HBO Max access in exchange for downloading the app on macOS. This download triggered a ClickFix-style attack, presenting users with instructions that, when followed, installed malware.

The malware was designed to steal sensitive data, including browser passwords, cookies, wallet data, and credentials from password managers on macOS. For Windows users, the domain served a similar ClickFix attack tailored for the Microsoft operating system. The attacker leveraged the verified corporate account to bypass user skepticism, creating a significant malvertising campaign that also included fake AI tools and system cleaners over a 48-hour period. Reddit has since paused the affected ads and is investigating the incident.

Disclaimer: This story has been auto-aggregated and auto-summarised by a computer program. This story has not been edited or created by the Feedzop team.

Read more news on

Property Code: 5571