Follow the latest coverage, related explainers and connected technology stories.
Attackers hijacked HBO Max’s verified Reddit account and posted 108 malicious advertisements over approximately 48 hours. The ads used the ClickFix technique to persuade users to execute malicious commands on Windows and macOS. Researchers linked the campaign to the PasteSwitch operation, which distributes data- and cryptocurrency-stealing malware.
Huntress detected campaigns that exploited sharing features, public content, and paid advertisements on platforms such as Claude, ChatGPT, and Grok to deceive users into downloading malware. The danger is that the malicious content appears within domains bearing the names of trusted platforms, reducing the usual warning indicators.