Attackers compromised the verified Reddit account u/hbomax and used it to run 108 malicious advertisements over roughly 48 hours. The ads impersonated HBO Max, AI-development tools, and macOS utilities, directing targets into a ClickFix campaign researchers call PasteSwitch that persuaded victims to copy and execute commands in a terminal or Windows Run dialog.
The copied commands selected payloads by operating system: macOS victims received MacSync and AMOS Helper stealers, while a Windows InstallFix chain loaded Amatera Stealer in memory. The campaign also deployed fake cryptocurrency wallets and crypto clippers, using direct-to-IP TLS communications and Binance Smart Chain smart contracts to rotate clipper command-and-control domains. Reddit paused the malicious ads and began an internal investigation to secure the compromised account.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
The controller address 0x3a35b409af86e79e8945d6a7ffb1dc59b8dbdf46 made 36 Binance Smart Chain mainnet C2-state changes between March and July 2026, rotating domains used by AnimateClipper and ZigClipper.
Reddit administrators reportedly paused the malicious advertisements associated with the compromised verified account and initiated an internal investigation involving its Security and Safety teams.
Hudson Rock and ADAMnetworks detailed PasteSwitch's macOS, Windows, and cryptocurrency-clipper delivery chains, including MacSync, AMOS Helper, InstallFix, Amatera Stealer, AnimateClipper, and ZigClipper. The report identified direct-to-IP C2, deceptive TLS signaling, victim-specific staging, malicious domains, IP infrastructure, and Binance Smart Chain contract-based clipper C2 indicators.
Attackers abused the verified u/hbomax Reddit account to publish 108 malicious advertisements over approximately 48 hours. The ClickFix lures impersonated HBO Max and software tools to deliver macOS stealers, Windows InstallFix/Amatera chains, fraudulent cryptocurrency wallets, and cryptocurrency clippers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 232 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
techcrunch.com
Open sourcemalware.news
Open sourcehudsonrock.com
Open sourceadamnet.works
Open sourcehudsonrock.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.