Hijacked HBO Max Reddit Account Used to Spread ClickFix Malware
Attackers gained unauthorized access to the verified HBO Max Reddit account and leveraged its trusted reputation to distribute malicious advertisements over a 48-hour window. The ClickFix technique exploited users' trust in a legitimate brand, tricking them into manually executing commands that installed information-stealing malware on both Windows and macOS systems. This incident highlights how compromised social media and community platform accounts can become powerful vectors for malware distribution, amplified by the credibility of a recognized brand. The extended 48-hour active window also reveals a failure in timely detection and incident response, allowing significant user exposure before the campaign was neutralized.
Tactical Insight
Immediate actions
- Rotate credentials and revoke all active sessions for any compromised social media or community platform accounts immediately upon detection.
- Enable multi-factor authentication (MFA) on all organizational social media and third-party platform accounts, including Reddit, Twitter/X, and LinkedIn.
Long-term improvements
- Implement a formal social media account inventory and assign dedicated owners responsible for periodic access reviews and credential hygiene.
- Establish a brand monitoring program that alerts security teams to anomalous posting activity or ad placements from official accounts.
- Train employees and communications teams to recognize and report suspicious account behavior, including unauthorized posts or ad campaigns.
Detection measures
- Configure alerts for login events from new devices or geographic locations on all official brand accounts across third-party platforms.
- Integrate social media activity logs into your SIEM to detect sudden spikes in posting frequency or ad spend as indicators of compromise.