Researchers discovered hundreds of fake ads running on the verified, legitimate HBO Max Reddit account directing users to malware-serving sites. When they pulled the string to see what was going on, they found a large-scale cybercriminal operation.
Dubbed PasteSwitch, this operation impersonated Claude, Codex, Alfred, HBO Max, Homebrew, GitHub, utility, and wallet pages. It also posed as several well-known brands. The attackers’ infrastructure is broad and far-reaching, and includes hundreds of websites. Some of them were registered in bulk in just seconds.
Through these fake websites, macOS stealers like AMOS and MacSync, Windows stealers like Amatera, AnimateClipper, and ZigClipper, and fake crypto wallet apps were distributed to users using ClickFix techniques.
Mac stealer campaign impersonates Claude, HBO Max, Homebrew, OpenAI Codex, GitHub, and more
In the past, a macOS cybercriminal operation might have included a couple of websites that could easily be checked by researchers and scanned by automated security systems. Today, that has changed.
Recently, Security researchers at Hudson Rock and ADAMnetworks, while examining fake ads on the legitimate HBO Max Reddit account, stumbled upon a large-scale macOS and Windows stealer. This is a financially motivated cybercriminal operation that was hijacked.
Stop Mac stealers before they grab your data
In addition to HBO Max, the bad actors behind PasteSwitch impersonated a number of macOS applications like Alfredo (the Mac productivity app) and Homebrew. These ClickFix malware-serving sites also impersonated OpenAI Codex through fake Codex and developer-tool pages, GitHub-themed lure pages, Claude, Ledger Wallet, Trezor Suite, Exodus, and macOS disk utilities, just to name a few.
The lure websites were coded to detect your operating system (OS) and serve the first payload specifically for your OS. That payload triggered a cascading sequence of events that connected your Mac to malicious sites, where eventually, a macOS or Windows stealer was dropped on your computer. All this could be done without you ever knowing.

The stealers used by PasteSwitch operators in this campaign for Mac users include AMOS and MacSync, as well as fake crypto wallet apps.
According to researchers, this operation began taking shape in July. In September, 64 typo-agent domains were registered through Unstoppable Domains within 61 seconds. This demonstrates the speed that modern attackers have when creating and rotating infrastructure.
What does this mean for you? In the same way that those 64 domains were created in seconds, attackers can create and rotate their malicious infrastructure and websites to launch new attacks.
In a nutshell, this is what a PasteSwitch attack looks like on your screen
Other than the scale and volume of this campaign, the attack chain technique used by PasteSwitch is nothing new.
In general, what you would see if you happen to fall into a PasteSwitch site is as follows:
- You follow an ad or search for something online and reach a fake PasteSwitch site.
- The site collects your system information. Depending on your OS, it might redirect you to another page or load a ClickFix page.
- If you follow the instructions on the ClickFix page, the attack begins to unfold. AMOS or MacSync will begin breaching your Mac.

“This incident demonstrates how attackers are increasingly weaponizing trust rather than relying purely on technical exploitation,” Ensar Seker, CISO at SOCRadar, told us.
“A malicious advertisement coming from a random account immediately raises suspicion, but an advertisement associated with a verified HBO Max account carries an implicit level of legitimacy,” Seker added.

“Once attackers compromise a trusted brand identity, they effectively inherit that trust and can use it as part of the social-engineering attack chain.”
Researchers found several indications that all these sites and malware linked back to the same operation. For example, they found API keys and telemetry keys hard-coded into multiple versions of the malware’s control scripts. The key was exactly the same in multiple malware samples.
Telemetry keys are used to send information to attackers from breached computers. This may include whether the malware was successfully installed, victim/system information, campaign or installation identifiers, and activity or status data.
The use of AI and automated tools allows any threat group (big or small) to take things to new heights and scale their threat campaigns in volume and speed.
For cybersecurity researchers, it’s a nightmare. Analyzing hundreds of malicious domains or online malicious infrastructure of this size is time-consuming and challenging. To make things even more difficult for security teams, PasteSwitch uses dynamic control and replaceable C2 and tasking, as well as a great number of crypto contracts and crypto addresses.
These types of large operations are not the standard today. However, precedents do exist. For example, in August, Microsoft documented more than 250 publicly accessible websites (front ends) in a macOS ClickFix campaign. This cluster of sites also used a technique called “gated,” in which cybercriminals use websites that can collect basic user data to redirect them to one site or another.
On July 15, Zscaler found 207 websites trying to convince Mac users to install MacSync. Rotating these domains and creating new ones is a walk in the park for cybercriminals who have the right tools.
As a reminder, both AMOS and MacSync, once they breach your wallet, will enter your Mac to steal sensitive data. They unlock resources, including your Keychain and other files, as well as steal your crypto wallet databases and replace cold wallet apps you might have with fake ones that try to phish your seed phrases and passwords.
AMOS and MacSync will also go into your browsers and steal data from there. This includes cookies and passwords. They can also breach password manager apps, install backdoors to receive commands, and create C2 attacker-controlled channels to send remote commands to your Mac and exfiltrate the data they stole.
Is PasteSwitch an AI-powered operation?
The researchers who looked into this campaign did not explicitly say that AI was used by PasteSwitch cybercriminals. That said, there are strong indications that it was.
For example, 108 ads on the hijacked HBO Max Reddit account across 5 lure groups ran for 48 hours, supported by a much larger surrounding infrastructure. Additionally, the operation was seen rapidly rotating websites and malicious infrastructure or domains, lure themes, telemetry endpoints, payloads, and malware delivery infrastructure, as well as creating crypto contracts and crypto addresses.

Impersonating brands like HBO Max, Codex, Claude, Alfred, Homebrew, Ledger, Trezor, GitHub, and others can also be done rapidly with generative AI. Furthermore, as mentioned, 64 domains were registered in just 61 seconds. This, combined with automated gates, platform detection, and a rapidly changing infrastructure, all point to substantial automation.
Another notable point is that, despite the numerous malicious resources that this campaign is using — or was using — different attack chains, including malware and gates that are functionally connected together.
Previous malware and Mac stealer campaigns have operated similarly, using many domains to target Windows and Mac gates. However, it has not been done at this combined front-end and back-end scale.
What can you do to stay safe from large-scale Mac stealer campaigns?
While cybersecurity research teams and law enforcement figure out these new types of large-scale AI-driven cybercriminal operations, there is much you can do on your end.
Mac stealers can only breach your Mac if you install them yourself
All these hundreds of sites, macOS stealers, lures, fake wallets, and apps need your “Install-Click” to breach your Mac.
“ClickFix is particularly effective because the attacker convinces the victim to execute the malicious action themselves,” Seker from SOCRadar said.
Instead of delivering a conventional executable that security controls may block, the victim is instructed to copy and paste commands into PowerShell, Windows Run, or macOS Terminal, said Seker.
Be mindful of fake installs, impersonation campaigns, and even legitimate sites
Users should always check the website URL of a site where they want to download something from to see if it matches the legitimate site. But this campaign shows that you should also be suspicious of legitimate sites, such as HBO Max, being impersonated.
Large-scale AI campaigns do not change user cybersecurity practices
“AI raises the speed and scale of attacks, but it doesn’t make good security practices obsolete. It makes them more important,” Nidhi Aggarwal, Chief Product Officer (CPO) at HackerOne, told us.
“For Mac users, I wouldn’t recommend fundamentally different security hygiene because of AI. I would recommend taking the existing fundamentals more seriously. Enable automatic updates, use multifactor authentication, install software from trusted sources, limit unnecessary permissions, and be cautious about giving AI agents broad access to email, files, credentials, or other applications,” said Aggarwal.
Get Moonlock. It will check installs, updates, and terminal commands
The Moonlock antivirus for Mac can help you mitigate the risks of macOS stealers out in the wild. Once you download the app, Real-Time Protection will run in the background. This silently checks everything you interact with for malware and suspicious behavior.

Real-Time Protection will check emails, files you download, software and update installs, and even Terminal commands to keep you safer from ClickFix attacks. If Moonlock finds anything, it will let you know what it is and why it is dangerous. It will then move it to Quarantine, where you can learn more about the threats your Mac encountered and remove them completely from your Mac.
The Moonlock app also ships with a customizable Malware Scanner, able to be optimized for depth or speed. Plus, it comes with a VPN for safe browsing and features that can help you strengthen your cybersecurity awareness and build safe digital habits.
You can check out and test-drive Moonlock for free for 7 days.
Final thoughts
PasteSwitch is not your usual macOS stealer campaign. However, it is something that has been in the making and on the horizon for a long time. Large-scale, rapid-speed delivery of Mac malware is gaining momentum. And technical elements like gates and cross-operating-system capabilities are becoming more complex to deal with.
As cybercriminals automate their campaigns, you can still stay safe by leveling up your tech stack. Be mindful of how social engineering techniques work. Ultimately, the entire malicious infrastructure is worthless unless you click on “Install” or copy and paste the malicious script that a fake site gave you into your Mac Terminal.
This is an independent publication, and it has not been authorized, sponsored, or otherwise approved by Apple Inc. Mac and macOS are trademarks of Apple Inc.
