Cybercrime intelligence firm Hudson Rock reported that hackers recently hijacked the Reddit account of HBO Max and used it to spread malware that steals passwords and encrypted wallet information. The attack page did not provide a normal installation package; instead, it required users to paste and execute commands in Terminal on Mac, or in Run and PowerShell on Windows.
Disguised as installation steps to induce execution
This tactic is known as ClickFix. It typically disguises malicious commands as regular steps for installing software, fixing errors, or completing human-computer verification. Since the information comes from hijacked accounts of well-known brands, users are more likely to let down their guard and carry out the related operations.
Researchers say that this attack not only targets account passwords but also attempts to obtain data from encrypted wallets. If users follow the prompts, their devices may be infected with malware, which could lead to the exposure of sensitive information stored locally.
Trojans will read contracts on the chain to obtain new addresses.
The report mentions that the attackers used clipboard hijacking Trojans and utilized the Binance Smart Chain ( BSC ) contracts as delivery points for variable control information. The malicious program would query the contracts on the blockchain to retrieve the latest control server addresses.
This means that even if hackers replace the backend servers, the Trojan can still continue to find new connection targets through the on-chain records, thereby maintaining its communication capability. Researchers believe that this approach makes it more flexible to attack infrastructure and also harder to cut off such attacks in one go.
Memorization words and transfer addresses are both high-risk targets.
Such actions are also related to the hijacking of encrypted clipboards. After a user copies a wallet address, the Trojan may replace it with an address controlled by the attacker. If the user proceeds with the transfer without verification, funds could be transferred to the wrong account.
Compared to address replacement, the risk of mnemonic phrase leakage is higher. Once the recovery phrase is stolen, attackers may directly take control of the corresponding wallet.
Researchers have pointed out that ClickFix has recently appeared multiple times in attacks targeting cryptocurrency users. In August, nearly 2,000 compromised WordPress websites were used for similar activities, stealing wallet information by forging verification prompts. Microsoft's research team also disclosed another round of attacks where hackers used fake CAPTCHA to induce Windows users to execute malicious commands, with the relevant instructions also obtained through BNB Chain.












