How cybercriminals are turning trusted platforms into platforms for launching malware


A compromised HBO Max Reddit account was used to spread malware through fake ads, demonstrating how attackers use trusted platforms to make scams appear legitimate. According to news platform The Register, the attackers took over a verified account and posted 108 malicious ads over about 48 hours, promoting fake HBO Max, fake artificial intelligence and developer tools. Users were redirected to fake websites using ClickFix, which tricked them into running malicious commands that could steal passwords, browser data and cryptocurrency information.

The incident is part of a larger pattern. Similar campaigns used verified social media accounts, popular software, online advertising and familiar safety pages to lure users into doing things they would normally avoid. The common element is trust: attackers create the impression that malicious content comes from a brand, service or product that people already recognize.

How the HBO Max attack worked

The HBO Max incident began with the hacking of an account authorized to post ads on Reddit. The attackers then used this account to distribute malicious advertisements. According to The Register, the campaign lasted about 48 hours and included 108 separate ads targeting Windows and macOS users.

The advertisement did not use the same bait. Some featured fake HBO Max software, while others promoted developer tools, artificial intelligence products, and utilities. This allowed attackers to target different groups of users rather than relying on a single message.

After clicking on the ad, the user may be taken to a website that appears to be legitimate. The site then used ClickFix, a social engineering technique that asks the victim to copy a command and paste it into a system tool. On Windows, this may be done using tools such as PowerShell or the Run dialog box, while Mac users may be prompted to use Terminal.

The important point is that the victim is persuaded to execute the malicious command. Obviously, there may be no suspicious file that the user could download. However, after running the command, malware may be installed.

Researchers said the broader PasteSwitch operation provides a variety of payloads, including information stealers, malware downloaders, cryptocurrency clippers and fake cryptocurrency wallet applications. This means the consequences could extend beyond a single infected device and include the theft of passwords, browser information and cryptocurrency-related data.

A similar attack appeared on X

In July 2026, researchers discovered sponsored ads on X from a verified account promoting a fake version of the Mac utility DynamicLake. According to a report from Malwarebytes, users who clicked on the ad were redirected to a similar website and were asked to open a terminal and paste installation commands.

The teams quietly installed information-stealing malware. Malwarebytes said the campaign combined a verified account, paid advertising, lookalike domain and ClickFix technique.

The similarities to the HBO Max incident are obvious. In both cases, attackers used a trusted entity or platform to deliver malicious messages to users. They then used familiar software as bait and relied on social engineering to convince victims to carry out the command.

Why trust matters

The incidents show why attackers are interested in legitimate accounts and advertising platforms. Malicious advertising from an unknown account can immediately raise suspicions. Ads appearing through a verified brand account may look completely different.

The verification badge alone does not make an ad safe, but it can make the scam more credible to the user. Attackers may also use familiar logos, names, and software interfaces to reinforce this impression.

This approach is not limited to social media. Attackers also use fake verification pages, search ads, and legitimate websites. In each case, the goal is the same: to reduce suspicion long enough for the victim to take the action the attacker wants.

Fake verification pages may appear on legitimate websites.

Malwarebytes reported several ClickFix campaigns in July that used fake Google and Cloudflare verification pages to make malicious instructions appear legitimate. Victims were shown what appeared to be a standard security or human verification process, but were instead asked to open a system utility and paste a command. Once executed, the command may install malware.

This method works by leveraging a familiar web experience. Users are used to encountering CAPTCHAs and human verification screens, especially on websites secured by services like Cloudflare. This way, asking for proof that someone is not a bot may raise less suspicion. The danger begins when the verification process asks the user to open a system tool and execute a command.

Attackers have also managed to place these fake verification pages on legitimate websites. In May 2026, Malwarebytes reported that more than 700 education and technology websites were compromised by exploiting a vulnerability in the Ghost content management system. The affected sites were used to display fake Cloudflare verification or CAPTCHA pages that asked visitors to copy and paste commands into Windows tools, potentially leading to the installation of malware.

This makes the attack difficult to identify since the original website itself may be legitimate. The compromise happens seamlessly, with the visitor seeing a familiar verification screen. Essentially, attackers can borrow both trust in a trusted website and familiarity with routine security checks to convince users to perform an action they would otherwise avoid.

So the broader problem is not limited to fake websites or malicious advertising. Legitimate digital infrastructure can also become part of an attack chain where attackers compromise accounts, websites or services and use them to deliver instructions that appear to be trustworthy.

Fake AI software is becoming another lure

The same pattern applies to artificial intelligence software. Fake OpenAI Code advertisements have been used to target Mac users, with criminals misrepresenting the malware as a legitimate developer tool.

The appeal is simple: developers and other users may actively search for popular AI tools and be more willing to install software if they believe it is from a well-known company.

Last month, Kaspersky Lab identified 92,000 malicious attacks in 2026 disguised as artificial intelligence services, with fake ChatGPT apps accounting for 49 percent of attacks. The fake Claude and Gemini bids accounted for 18 percent each.

The researchers also identified more than 15,000 samples of malware disguised as artificial intelligence agent software. These include Trojans, spyware, exploits, downloaders, droppers and backdoors.

Leave a Reply

Your email address will not be published. Required fields are marked *