Compromised HBO Max Reddit Account Exposed a Cross-Platform PasteSwitch ClickFix Campaign

Summary
Researchers traced 108 ads posted over 48 hours from a compromised verified HBO Max Reddit account to PasteSwitch, a cross-platform operation delivering macOS and Windows stealers, fake wallet apps, and cryptocurrency clippers.
Key points
- Attackers used the verified u/hbomax account to post 108 malicious ads in 48 hours, directing users to fake software sites and ClickFix prompts that told them to run commands.
- The PasteSwitch infrastructure qualified visitors and routed them to different payloads, lures, and delivery services across platforms.
- On macOS, payloads included MacSync and AMOS variants that could steal credentials and other data, plus fake Ledger, Trezor, and Exodus apps designed to capture wallet recovery phrases.
- On Windows, InstallFix used mshta and PowerShell to load Amatera Stealer in memory; its direct-IP C2 connection presented facebook.com through TLS SNI and HTTP authority.
- AnimateClipper and ZigClipper used Binance Smart Chain contracts to retrieve changeable C2 domains; researchers observed 36 mainnet changes from March to July 2026.
- Reddit paused the affected ads and began an investigation with its Security and Safety teams.
- Researchers identified recurring execution, routing, TLS, and smart-contract signals that could help track the operation as its lures and domains change.
Article Details
- Attack Vectors
- Attackers used the compromised, verified u/hbomax Reddit account to publish 108 malicious advertisements over 48 hours. The ads promoted HBO Max, AI-tool, and macOS-utility lures.
- Fraudulent landing pages used ClickFix prompts to persuade visitors to paste attacker-supplied commands into a terminal or run dialog. The delivery system selected different routes based on visitor qualification and platform.
- The macOS routes used curl | zsh commands to deliver MacSync, AMOS helpers, and fake cryptocurrency-wallet applications. The fake wallets sought BIP39 recovery phrases.
- The Windows route prompted victims to run an mshta command that retrieved an MP3/HTA polyglot. Subsequent stages used PowerShell and loaded Amatera Stealer into memory.
- AnimateClipper and ZigClipper replaced cryptocurrency addresses in the clipboard and retrieved changeable C2 domains from Binance Smart Chain contracts.
- Defensive Notes
- Reddit administrators paused the affected advertisements and began an investigation to secure the verified account.
- The researchers recommend examining process ancestry for copied-command execution and correlating route tokens, API keys, and telemetry endpoints across changing domains.
- Correlating destination IP, TLS SNI, certificates, and DNS can reveal Amatera traffic that presents facebook.com while connecting to an attacker IP.
- Monitoring contract setter transactions can reveal newly published clipper C2 domains.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | aforvm[.]com | AMOS helper and tasking domain. |
| DOMAIN | aidevmaster[.]com | MacSync delivery and control domain. |
| DOMAIN | alfredaps[.]com | Copied-command lure listed in the IOC inventory. |
| DOMAIN | applediag[.]com | Domain in the operation's provisioning neighborhood. |
| DOMAIN | arkypc[.]com | AMOS helper and tasking domain. |
| DOMAIN | basequill9[.]com | macOS loader-delivery domain. |
| DOMAIN | beaocnagent[.]com | MacSync delivery and control domain. |
| DOMAIN | bright-links[.]com | Copied-command lure listed in the IOC inventory. |
| DOMAIN | broadwalkindia[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | camaligsalvatrefoils[.]com | Malicious-ad click-tracking domain. |
| DOMAIN | canvas-35[.]com | macOS loader-delivery domain. |
| DOMAIN | carlessclapped[.]com | Clipper C2 domain decoded from a contract setData transaction. |
| DOMAIN | cehamilton[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | chatgpt-safepage[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | cim-kolea[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | claud-tips[.]com | Provisioning-linked malicious lure domain. |
| DOMAIN | claude-tools[.]com | Provisioning-linked malicious lure domain. |
| DOMAIN | clean-disk-guide[.]com | Copied-command lure listed in the IOC inventory. |
| DOMAIN | clean-disk-tools[.]com | Provisioning-linked malicious lure domain. |
| DOMAIN | cli-desktop[.]com | Copied-command lure listed in the IOC inventory. |
| DOMAIN | cli-guides[.]com | Provisioning-linked malicious lure domain. |
| DOMAIN | cli-stack[.]com | Copied-command lure listed in the IOC inventory. |
| DOMAIN | clveeragent[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | cmux-lab[.]com | Provisioning-linked malicious lure domain. |
| DOMAIN | code-desktop[.]com | Malicious AI-tool advertisement destination and lure. |
| DOMAIN | codex-craft[.]com | Malicious AI-tool advertisement destination and lure. |
| DOMAIN | codex-notes[.]com | Copied-command lure listed in the IOC inventory. |
| DOMAIN | codex-paths[.]com | Provisioning-linked malicious lure domain. |
| DOMAIN | congiagent[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | cosimcagent[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | crisp-paths[.]com | Provisioning-linked malicious lure domain. |
| DOMAIN | denverplumbingandwaterheater[.]com | MacSync delivery and control domain. |
| DOMAIN | desktop-version[.]com | Windows payload-staging domain. |
| DOMAIN | dogtrainersgeorgia[.]com | MacSync delivery and control domain. |
| DOMAIN | ember-bridge[.]com | September telemetry and delivery domain. |
| DOMAIN | euquiz[.]space | Address-reuse indicator in the threat-infrastructure inventory. |
| DOMAIN | fern-plume[.]com | AMOS helper and tasking domain. |
| DOMAIN | filequanticore[.]com | Copied-command lure whose page loaded the malicious command through JavaScript. |
| DOMAIN | filesiriuscore[.]com | Copied-command lure listed in the IOC inventory. |
| DOMAIN | flame-guard[.]cc | Clipper C2 domain decoded from a contract setData transaction. |
| DOMAIN | flutelikelurkerunsinewy[.]com | Malicious-ad click-tracking domain. |
| DOMAIN | gatemaden[.]space | MacSync delivery and control domain. |
| DOMAIN | getnova[.]top | Domain in the operation's provisioning neighborhood. |
| DOMAIN | gigappyworld[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | glowmedaesthetics[.]com | MacSync delivery and control domain. |
| DOMAIN | glrack[.]com | Fake cryptocurrency-wallet application delivery domain. |
| DOMAIN | gogolfonline[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | grove-12[.]com | AMOS helper and tasking domain. |
| DOMAIN | harbor-29[.]com | AMOS helper and tasking domain. |
| DOMAIN | hbomax-macos[.]com | Malicious HBO Max-themed advertisement destination and copied-command lure. |
| DOMAIN | hbomaxx[.]app | Malicious HBO Max-themed advertisement destination and copied-command lure. |
| DOMAIN | hbomaxx[.]us | Fraudulent HBO Max landing page that delivered a ClickFix prompt. |
| DOMAIN | hbubagent[.]com | MacSync delivery and control domain. |
| DOMAIN | heroestales[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | hindustanagency[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | homebrwmac-hub[.]com | Copied-command lure listed in the IOC inventory. |
| DOMAIN | houstongaragedoorinstallers[.]com | MacSync delivery and control domain. |
| DOMAIN | lakhov[.]com | AMOS helper and tasking domain. |
| DOMAIN | lalandscapelighting[.]com | MacSync delivery and control domain. |
| DOMAIN | leaf68[.]com | macOS loader-delivery domain. |
| DOMAIN | loop-lumen[.]com | Fake cryptocurrency-wallet application delivery domain. |
| DOMAIN | macdeveloperhub[.]com | Provisioning-linked malicious lure domain. |
| DOMAIN | macfixguide[.]com | Provisioning-linked malicious lure domain. |
| DOMAIN | macstoragetips[.]com | Domain in the operation's provisioning neighborhood. |
| DOMAIN | marbellaresales[.]com | MacSync delivery and control domain. |
| DOMAIN | microsoftupdater[.]info | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | mpasvw[.]com | AMOS helper and tasking domain. |
| DOMAIN | muse-code-ide[.]com | Provisioning-linked malicious lure domain. |
| DOMAIN | node-slate[.]com | AMOS helper and tasking domain. |
| DOMAIN | nova-desk[.]top | Domain in the operation's provisioning neighborhood. |
| DOMAIN | nova-fix[.]top | Domain in the operation's provisioning neighborhood. |
| DOMAIN | nova-hub[.]top | Domain in the operation's provisioning neighborhood. |
| DOMAIN | nova-labs[.]top | Domain in the operation's provisioning neighborhood. |
| DOMAIN | nova-tools[.]top | Domain in the operation's provisioning neighborhood. |
| DOMAIN | novastacktips[.]com | Domain in the operation's provisioning neighborhood. |
| DOMAIN | oakenfjrod[.]ru | Windows payload-staging domain. |
| DOMAIN | opendisplay[.]us | Provisioning-linked malicious lure domain. |
| DOMAIN | ouilov[.]com | AMOS helper and tasking domain. |
| DOMAIN | papartybus[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | perchframe15[.]com | macOS loader-delivery domain. |
| DOMAIN | pine63[.]com | macOS loader-delivery domain. |
| DOMAIN | pinescope11[.]com | MacSync delivery and control domain. |
| DOMAIN | press29[.]com | macOS loader-delivery domain. |
| DOMAIN | pressureulcerlawyer[.]com | MacSync delivery and control domain. |
| DOMAIN | rectangleap[.]com | Provisioning-linked malicious lure domain. |
| DOMAIN | remotion-skills[.]com | Domain in the operation's provisioning neighborhood. |
| DOMAIN | restoremental[.]com | MacSync delivery and control domain. |
| DOMAIN | rudder-moss[.]com | September telemetry and delivery domain. |
| DOMAIN | sgaaagent[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | sic180[.]com | SIC Windows-route domain. |
| DOMAIN | sprieagent[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | storageprofiler[.]com | Gated copied-command lure listed in the IOC inventory. |
| DOMAIN | thepullmanfolkestone[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | trekmesh15[.]com | macOS loader-delivery domain. |
| DOMAIN | umapla[.]com | Fake cryptocurrency-wallet application delivery domain. |
| DOMAIN | verse-18[.]com | AMOS helper and tasking domain. |
| DOMAIN | wantsellonline[.]com | Domain in the operation's teardown and delivery neighborhood. |
| DOMAIN | weaveridge7[.]com | September telemetry and delivery domain. |
| DOMAIN | wuess[.]com | September telemetry and delivery domain. |
| HOSTNAME | apple[.]clean-disk-guide[.]com | Malicious macOS-utility advertisement destination. |
| HOSTNAME | br[.]hugo-lapp[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | cf[.]hugo-mapp[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | cladesktop[.]gitlab[.]io | Specific malicious copied-command lure hosted on shared infrastructure. |
| HOSTNAME | cw[.]hugo-lapp[.]lat | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | dau[.]hugo-mapp[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | dmt[.]unguidedfreewill[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | doh[.]hugo-mapp[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | ed[.]hugo-lapp[.]lat | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | en[.]hugo-mapp[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | esp[.]hugo-mapp[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | fcp[.]unguidedfreewill[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | fd-api-irc[.]velqo7[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | fd-api-irf[.]velqo7[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | fd-api-iris[.]velqo7[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | fd-api-irs[.]velqo7[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | fd-api-rop[.]velqo7[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | fd-api-zog[.]velqo7[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | fd[.]gstats-api-contact[.]cc | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | fd[.]gstats-api-contd[.]cc | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | fd[.]hugo-lapp[.]lat | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | fr[.]hugo-mapp[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | habar55[.]namebright[.]bike | Indicator printed in the source's SIC Windows-routes inventory; the source does not separate its components. |
| HOSTNAME | io[.]hugo-lapp[.]lat | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | jup[.]unguidedfreewill[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | kffd3[.]vexlatech[.]cc | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | kffd3[.]vogueatelier[.]cc | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | kr[.]hugo-lapp[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | lb[.]propertyfind[.]cc | Clipper C2 domain retrieved through a smart contract. |
| HOSTNAME | mgo[.]gstats-api-contact[.]cc | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | paf[.]hugo-mapp[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | pf[.]hugo-mapp[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | pkg[.]vogueatelier[.]cc | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | pt[.]hugo-lapp[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | sdx[.]unguidedfreewill[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | smart[.]hugo-mapp[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | sp1[.]gstats-api-coni[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | sp13[.]gstats-api-coni[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | sp13[.]gstats-api-cont[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | st[.]hugo-lapp[.]lat | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | static[.]quorashift[.]cc | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | td[.]hugo-lapp[.]lat | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | tnt[.]unguidedfreewill[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | wdm[.]unguidedfreewill[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | wdm[.]velqo7[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | wdx[.]unguidedfreewill[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | wdx[.]velqo7[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | wix[.]velqo7[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | xn--b1ahgbfifq[.]gstats-api-cont[.]co | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | xn--b1aluem3j[.]gstats-api-contd[.]cc | Clipper C2 domain decoded from a contract setData transaction. |
| HOSTNAME | xn--i-ctbr1afp[.]gstats-api-contd[.]cc | Clipper C2 domain decoded from a contract setData transaction. |
| IPV4 | 138[.]124[.]93[.]32 | AMOS helper/contact exfiltration indicator in the cited Microsoft IOC list. |
| IPV4 | 164[.]90[.]161[.]147 | September macOS post-execution HTTP contact endpoint. |
| IPV4 | 165[.]22[.]199[.]85 | September macOS telemetry and /contact exfiltration endpoint. |
| IPV4 | 168[.]100[.]9[.]122 | AMOS helper/contact exfiltration indicator in the cited Microsoft IOC list. |
| IPV4 | 172[.]236[.]51[.]169 | Observed origin of a gated malicious storageprofiler lure. |
| IPV4 | 176[.]53[.]159[.]66 | IP associated with the teardown, TLS, and Windows executable delivery cluster. |
| IPV4 | 199[.]217[.]98[.]33 | AMOS helper/contact exfiltration indicator in the cited Microsoft IOC list. |
| IPV4 | 38[.]244[.]158[.]103 | AMOS helper/contact exfiltration indicator in the cited Microsoft IOC list. |
| IPV4 | 38[.]244[.]158[.]56 | AMOS helper/contact exfiltration indicator in the cited Microsoft IOC list. |
| IPV4 | 45[.]94[.]47[.]204 | AMOS helper enrollment, task-polling, and acknowledgement endpoint. |
| IPV4 | 62[.]60[.]226[.]69 | IP associated with shared provisioning for the Nova and macOS-tool cluster. |
| IPV4 | 77[.]91[.]65[.]13 | Amatera direct-to-IP TLS C2 endpoint that presented facebook.com as its SNI. |
| IPV4 | 92[.]246[.]136[.]14 | AMOS helper fallback /contact exfiltration endpoint. |
| SHA256 | 008e04a7807f9ed59d77942b1d268e4a93bb82316346f48e5f5b663233db3fff | Freshfolio lure-artifact hash. |
| SHA256 | 013e587247324cfa3005443d2b8036f9a434cafafa1d8a56a6f5637b3dd9d3c1 | Cladesktop fallback-page hash. |
| SHA256 | 02ac1914fcb4efae0699571751acd700ef0a1933312cd37e72bb7f37bacf4776 | Homebrew lure-artifact hash. |
| SHA256 | 06a3d3bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b | Houston MacSync shell-stage hash. |
| SHA256 | 06c74829d8eee3c47e17d01c41361d314f12277d899cc9dfa789fe767c03693e | Older MacSync Mach-O hash. |
| SHA256 | 0d58616c750fc8530a7e90eee18398ddedd08cc0f4908c863ab650673b9819dd | Glowmedaesthetics MacSync shell-stage hash. |
| SHA256 | 12f6fde9d8058292ad1fb869352eebd615aa59c526a481a39fb52aa59e368d0d | Oakenfjrod Polymarket response hash. |
| SHA256 | 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4 | Fake Trezor application archive hash. |
| SHA256 | 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505 | Pinescope11 MacSync shell-stage hash. |
| SHA256 | 1ba14ee44de95a3e6dcb9866cd00015dbf37f078a74362a827b21c8b2ec48a1a | Malicious copied-command data hash. |
| SHA256 | 23bec473632af324b0a271f6b0575ea3d3174af7042ee5d582cb739714a35af8 | AnimateClipper sample associated with Broadwalkindia. |
| SHA256 | 249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938 | Trekmesh15 AMOS helper shell-stage hash. |
| SHA256 | 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 | Clipper archive hash; the article says its extracted payload was classified as AnimateClipper. |
| SHA256 | 2f04ba77bb841111036b979fc0dab7fcbae99749718ae1dd6fd348d4495b5f74 | Oakenfjrod cloude-stage hash. |
| SHA256 | 31cf473bb93abef0760d4992d45bafcd936edb7c26193c175f8491f8ffaef0e0 | AnimateClipper sample associated with Cehamilton. |
| SHA256 | 3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92541a24 | Recovered InstallFix PowerShell stage hash. |
| SHA256 | 407aaecabee599cb29dbb3cf177ed77b67f65d63f456c7abeda5834c0d36ed5f | AnimateClipper sample associated with Hindustanagency. |
| SHA256 | 439f01ee546eabbdbcc02c0312cf3de28877ed8fcba80e46da88b76b02527a66 | Shellcode-loader PowerShell stage hash. |
| SHA256 | 480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5 | InstallFix /claude carrier hash. |
| SHA256 | 48cc0941b4129bfaeb6948de49dc7c81456e92907b3ea6bdcef5ff186dddf200 | Fake Trezor application Mach-O hash. |
| SHA256 | 52385473e1a64ae5b7a3b79f145304e6b2c5db53e8883e6beede41821c08673f | Bright Links lure-artifact hash. |
| SHA256 | 5a9a3ce9ff74d7823737b184330134b25a4f36fc1d268789229f8de16832508c | Filequanticore and Filesirius malicious-lure artifact hash. |
| SHA256 | 5ae085cb918abaeb83b4819106534247cfd30f30c77cbcc7806fbf99e12234fb | Harbor helper hash. |
| SHA256 | 5e8ad983129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad | InstallFix MP3/HTA carrier hash. |
| SHA256 | 5ee86cbcd296e0998ca20ee65a7506fb3baecfb7ce98eede29bff1a6a6e0fc95 | AnimateClipper sample associated with Hindustanagency. |
| SHA256 | 6705033c16d499d65b79f0f8f459a8ea214ae85aedffb3d25f68ba26e455f136 | wuess configuration-body hash. |
| SHA256 | 6759c72365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7 | SIC MP3/HTA payload hash. |
| SHA256 | 6d9ced8d62655d1a0ddc0d6b5359a10e921b4b2b3b1000dcf96b240f2fa79662 | Cli-desktop lure-artifact hash. |
| SHA256 | 7a4c15c5f056322ceb9a16fd74374ec0e85aacbaeeb6042ff34b9c415e900864 | Cladesktop wrapper hash. |
| SHA256 | 825f0358da26a5cd85076be4586c4125ea5958235f3d9669ea3bf60c0edfc5b2 | Harbor AMOS helper shell-stage hash. |
| SHA256 | 86d0c50cab4f394c58976c44d6d7b67a7dfbbb813fbcf622236e183d94fd944f | Glowmedaesthetics MacSync shell-stage hash. |
| SHA256 | 8c469b571875c6ba0009237379ba0a23b716db6d97724a81a7032a2e4b3456b6 | Cladesktop cross-platform lure-artifact hash. |
| SHA256 | 8d88b558dc9edbc4fdb66eb2451fd5f4df49266921346d2db1191cf23f0d13dc | Fake Exodus application Mach-O hash. |
| SHA256 | 91b192d28380c77bda19a142c8979d03b3409ca819c07e6dabae0c73a2ab2360 | Storageprofiler gated-lure artifact hash. |
| SHA256 | 93d986f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae | Arkypc loader hash. |
| SHA256 | 97f9e987cbd9de6e853c1adcc7614a8d77d4216d63473e7a1f0f6356c5f0e771 | Zig-contract-associated sample hash. |
| SHA256 | 9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e849cd96 | Dogtrainers MacSync shell-stage hash. |
| SHA256 | 9f26da2456f30b1e10c9aaee4fbf4cbab07912177366aca7fa1103be08a026ff | Codex Notes lure-artifact hash. |
| SHA256 | a69fb9b56a10c8616e76b20a6900842737e16077796aa195b86b71407b8e79b9 | Diskclearing lure-artifact hash. |
| SHA256 | a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287e6a411 | Recovered metadata mdworker_shared component hash. |
| SHA256 | ac90360ac4d8c2eb2585daa867d085d2fb12b859bed6c3a472a738cd08e55383 | Denver MacSync shell-stage hash. |
| SHA256 | bc9165c426258d33799107d41a1e692504d7e69e02762475ab3b8cbcd19d5d40 | AnimateClipper sample associated with Cim-kolea. |
| SHA256 | cf8d03a0de9e29e3f6a81606443cbf9df2167e95435f88ede747415d4b7e84ed | Filequanticore malicious-script hash. |
| SHA256 | d1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c | Pressureulcerlawyer MacSync shell-stage hash. |
| SHA256 | d4150c1c97f047c6edb14767bf1efa8f9e37d63b124f38f27da4ef52d570aac2 | AccountsHelper service component hash. |
| SHA256 | d4cfab5e052df4c049f258e226d11825cb37b0359be454b83241edd59b295f08 | AnimateClipper sample associated with Hindustanagency. |
| SHA256 | d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb | Amatera PE hash. |
| SHA256 | d5a60dedf71308f5971269b7a63903e4b68992c392a0368f1dd03cb7e4bcefbc | Oakenfjrod cloude-stage hash. |
| SHA256 | d72df956a51b1ec0af1e1d375a5704538d2e32688259c14aed39cf1e9d0d770a | Cli-stack lure-artifact hash. |
| SHA256 | d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540 | Aidevmaster MacSync shell-stage hash. |
| SHA256 | dbe8f391291a66a509d5a0144ece8e61789657f96bac14f786293bb4d2ca21ac | Decoded malicious PowerShell layer hash. |
| SHA256 | e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c | Arkypc helper hash. |
| SHA256 | ebb2a2f9f58d0908848399ffcb3a254e9171a8c14daeeae7fc042376372802f4 | Oakenfjrod cloude-stage hash. |
| SHA256 | ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331 | Recovered x86 shellcode hash. |
| SHA256 | ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb | Fake Exodus application archive hash. |
| SHA256 | ecfaa20f25e11878686249c7094706bc3dcd2dc0ace0f2932a39d1bfdac85863 | Older MacSync Mach-O hash. |
| SHA256 | ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7 | Lalandscapelighting MacSync shell-stage hash. |
| SHA256 | eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009 | September macOS payload hash. |
| SHA256 | f122d596ac6f5bb26ec69ab5fa68506da71d0f72bba5533c913dedd0314855e7 | Filequanticore page-loader hash. |
| SHA256 | f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7 | Recovered metadata mdworker component hash. |
| SHA256 | f771f4717ed04f723b30f9e0424cc2f630f1ffe47857502edd27c3c40c609320 | Cladesktop Wasm artifact hash. |
| SHA256 | f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e | Fake Ledger application archive hash. |
| SHA256 | fbc6e1867de39feb53f62f8fe805b9dee8ca66e751243731d1db3974eba07e97 | Restoremental MacSync AppleScript hash. |
| SHA256 | fdfd0b06cb31d68146dbb5ffb45b82ca1b59a7b4f62f917a990a9c3bd01654ab | AnimateClipper sample associated with Broadwalkindia. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationWindows stages used an MP3/HTA polyglot, arithmetic fog, and opaque predicates to obscure payload execution.T1053.005 · Scheduled TaskThe InstallFix HTA created a scheduled task.T1059.001 · PowerShellThe Windows InstallFix chain launched PowerShell for subsequent payload stages.T1059.004 · Unix ShellmacOS victims were instructed to run curl | zsh commands that fetched and executed payloads.T1071.001 · Web ProtocolsAn AMOS helper used HTTP API endpoints for enrollment and continuing task polling.T1204 · User ExecutionClickFix overlays persuaded visitors to execute attacker-supplied commands themselves.T1218.005 · MshtaThe Windows ClickFix prompt used mshta to retrieve and run an MP3/HTA polyglot.T1555.003 · Credentials from Web BrowsersMacSync exfiltrated browser credentials.T1562.001 · Disable or Modify ToolsThe InstallFix HTA disabled AMSI before later PowerShell stages ran.
People
Alex CuttsFirst reported encountering the suspicious advertisement from the verified u/hbomax account.EmilianoThe Matrix Project contributor thanked for additional assistance with the research.KirkADAMnetworks researcher involved in the joint investigation and author of a companion technical report.LostshDocumented a Homebrew ClickFix campaign that the article says used the same loader grammar and telemetry paths.TuxxinWhack.sh contributor thanked for additional assistance with the research.
Malware
Amatera StealerIn-Memory Loading: The subsequent stages used arithmetic fog, opaque predicates, and shellcode to inject the Amatera Stealer PE directly into memory without touching the disk.AMOSThe macOS Branch: MacSync, AMOS, and Fake WalletsAnimateClipperFor persistent clipboard replacement (swapping crypto addresses when victims try to copy or paste), PasteSwitch delivered AnimateClipper and ZigClipper.MacSyncThe macOS Branch: MacSync, AMOS, and Fake WalletsZigClipperFor persistent clipboard replacement (swapping crypto addresses when victims try to copy or paste), PasteSwitch delivered AnimateClipper and ZigClipper.
Vendors
Hudson RockThrough joint research conducted by Hudson Rock and Kirk from ADAMnetworks (with additional thanks to Tuxxin from Whack.sh and Emiliano from The Matrix Project), we can confirm this incident is part of a massive,RedditHBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation
Products
CavalierOverview of the new Threat Feeds monitoring options available inside Cavalier, including C2 Intelligence, ClickFix Monitor, and PhaaS Feed.HBO MaxHBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operationmacOSThis operation spans macOS stealers, Windows loaders, deceptive TLS tactics, and contract-controlled cryptocurrency clippers.Microsoft WindowsThis operation spans macOS stealers, Windows loaders, deceptive TLS tactics, and contract-controlled cryptocurrency clippers.RedditHBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation