Threat actors successfully hijacked the official Max (formerly HBO Max) Reddit account to distribute malware through a sophisticated social engineering campaign. By leveraging the trust associated with a verified corporate account, the attackers promoted malicious links disguised as legitimate support pages to lure unsuspecting users.
The campaign utilizes the "ClickFix" technique, which tricks victims into executing malicious PowerShell commands directly into their systems under the pretense of fixing browser issues. This method effectively bypasses traditional security warnings by convincing users to manually initiate the infection process, typically resulting in the deployment of information-stealing malware.
Top comments (0)