Compromised Streaming Account Pushes Crypto Wallet Malware
A verified social media profile belonging to a major television streaming service was recently compromised to distribute malware aimed at extracting cryptocurrency wallet data. Over a 48-hour window, attackers used the hijacked account to post exactly 108 malicious advertisements targeting digital asset holders.
The breached account was the officially verified Reddit profile for HBO Max, a property owned by Warner Bros. Discovery. According to reports, a Reddit user named Alex Cutts first detected the fraudulent campaign on September 6, 2026, flagging the suspicious activity in the r/cybersecurity subreddit. Following the public discovery, Reddit confirmed the compromise, locked the advertising-authorized account, and purged all associated malicious links from the platform.
Out of the 108 published ads, 46 utilized lures directly related to the streaming service itself, such as falsely advertising a native macOS application. Another 36 advertisements were designed to impersonate OpenAI's Codex. The campaign was jointly analyzed by security research firms ADAMnetworks and Hudson Rock, who classified the attack as part of a larger, cross-platform malvertising initiative they named "PasteSwitch."
"The threat actors squeezed as much value as possible out of the verified account's status, pivoting quickly when domains were burned," noted Hudson Rock regarding the campaign's rapid execution.
Social Engineering and Payloads

To infect victims, the attackers utilized a social engineering method known as "ClickFix." This technique presents users with fake anti-bot checks or CAPTCHA screens, actively deceiving victims into copying and pasting malicious code directly into their system interfaces, such as Windows PowerShell, the Command Prompt, or the macOS Terminal.
Depending on the operating system targeted, the injected code delivered different information-stealing payloads. Windows devices were infected with the Amatera infostealer, while Apple macOS users received either the AMOS or MacSync infostealers.
These malicious programs were specifically designed to harvest sensitive digital asset data, including cryptocurrency wallet recovery phrases, commonly known as seed phrases. The malware also targeted browser credentials, saved passwords, Telegram data, and Apple Notes. Additionally, the campaign deployed cryptocurrency clipboard hijackers. These specific "crypto clippers" monitor a victim's clipboard for copied wallet addresses and secretly replace them with an address controlled by the attacker just before a transaction is finalized.
Ensar Seker, CISO at SOCRadar, explained how the attackers leveraged the account's prominent status. "A malicious advertisement coming from a random account immediately raises suspicion, but an advertisement associated with a verified HBO Max account carries an implicit level of legitimacy. Once attackers compromise a trusted brand identity, they effectively inherit that trust and can use it as part of the social-engineering attack chain," Seker stated.
Unconfirmed Asset Losses
The overall financial damage and the total number of infected users currently remain unconfirmed. Reddit has declined to disclose the specific click or targeting metrics for the malvertising campaign, leaving the exact scale of the reach and any resulting cryptocurrency asset losses entirely unknown.


