Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware. A Reddit user uncovered the infostealer ads on September 6, noting that the ad showed u/hbomax as the author โ this is the verified HBO Max account โ and advertised a macOS app for HBO Max. The streaming service does not offer a native client for the Mac. Anyone who clicked on the malicious ad would then be taken to a โsomewhat-legitimateโ looking landing page (hbomaxx[.]us) that includes a join/download button. Clicking the button produced instructions telling the user to copy and paste a command into Terminal on macOS. The Reddit security sleuth described that as โthe classic infostealer/clickfix paste this command to download,โ noting that they tested all of this in a sandboxed environment, and didnโt actually run the executable on their machine. โMy guess is that the Reddit account is compromised,โ they concluded. Three days later, Reddit paused the infostealer-dropping ads, and an admin said the social media platformโs safety and security teams were investigating what happened. HBO Maxโs parent company Warner Bros. Discovery didnโt immediately respond to The Registerโs inquiries about the account takeover - including who hijacked the streaming serviceโs Reddit account and how they did it. Maybe someone who didnโt like the House of the Dragon season 3 finale? We will update this story if and when we hear back. Researchers at Hudson Rock and ADAMnetworks analyzed the ads, and in a couple of reports said the HBO Max account hijacking was part of a โmassive 48-hour malvertising blitzโ that pushed 108 distinct ads using multiple software lures. They named the campaign PasteSwitch, and said it serves up targeted malware aimed at victimsโ operating system - either macOS or Windows. The payloads include infostealers, malware loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications. The cryptocurrency clippers - PasteSwitch delivers either AnimateClipper or ZigClipper - also provide blockchain-based command-and-control fallbacks for the attackers. They use Binance Smart Chain (BSC) contracts to dynamically fetch whatever C2 domain the crooks are using at any given time. โBetween March and July 2026, researchers observed 36 mainnet changes executed by the same attacker controller address,โ Hudson Rock said. โBecause the C2 domain is hosted directly on the blockchain, the infrastructure demonstrates dynamic resilience, allowing the threat actors to easily rotate burned domains.โ In addition to HBO Max, the attackers used developer-tool, disk-cleaner, and AI-themed lures, including fake OpenAI Codex ads, which crims have previously used to push Mac malware. Of the 108 ads, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com). โThe campaign proves once again why trusted distribution channels are becoming prime targets for infostealer delivery,โ Hudson Rock co-founder and CTO Alon Gal said in a LinkedIn post. It also shows that miscreants continue to make heavy use of ClickFix attacks, so thereโs little sign this social engineering method is going away anytime soon.ยฎ
The International Meteor Organization (IMO) is watching for fireballs again, but much of its website remains offline after a cyberattack that it says will take weeks to recover from. The Belgium-based nonprofit, which coordinates meteor observations and brings together amateur and professional astronomers worldwide, is currently serving visitors a stripped-down holding page explaining the outage. "We recently suffered a cyberattack that dealt a critical blow to aging infrastructure, taking much of our site offline," the organization said. "We expect several weeks of partial downtime as we transition to new infrastructure and services." IMO has not disclosed when the attack occurred, how the attackers gained access, or whether they accessed or encrypted any data. The organization collects reports from people who spot unusually bright meteors, or fireballs, and uses those observations to help document and analyze events. Its notice says it prioritized restoring that capability after the attack. "We prioritized restoring fireball reporting, and it is available again," IMO said. "If you saw a fireball or a bright light in the sky, you can still submit your observation." Other parts of the site remain unavailable while the organization rebuilds its infrastructure. IMO's warning that the process will take several weeks suggests this is more than a case of simply restoring a compromised web server, although the organization has not disclosed the extent of the damage. The incident also leaves some unanswered questions about the data held on the affected systems. IMO operates services used by meteor observers and members around the world, but has not said whether information belonging to users or contributors was exposed during the attack. The Register asked IMO when the attack occurred, which systems were affected, whether any data was compromised, and whether it has identified who was responsible, but has not yet received a response. IMO is used to documenting things that burn up spectacularly. It probably didn't expect its IT infrastructure to join them. ยฎ
British bank Revolut exposed sensitive customer information after falling for fraudulent requests sent from a legitimate government agency's email domain. In a statement shared with The Register, Revolut confirmed the attack, but did not specify how many customers were affected. The company also did not provide a list of affected data types. However, blockchain investigator ZachXBT, who shared Revolut's customer notifications on Friday, claimed the exposed information includes know-your-customer (KYC) data. Whichever identity document customers submitted as part of the account registration process โ passport or driver's license โ was compromised, as was the verification selfie submitted through the app, according to the shared emails. The notifications also list account statements, IBANs, withdrawal records, and full transaction histories, including Bitcoin transactions, among the exposed data. Other exposed details include full names, dates of birth, home and email addresses, phone numbers, and occupations. Sources close to the fintech say only a small proportion of its customers were impacted. They say ongoing investigations and confidentiality obligations prevent Revolut from providing further details. Revolut said it exposed the data to an unauthorized third party after they submitted requests from a genuine government agency's email domain. The company, which received approval to launch its UK bank in March, did not identify the government agency, but said it informed the relevant officials of the findings. "Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information," the spokesperson said. "Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators. Revolut systems and customer funds are unaffected. "We have contacted the limited number of impacted individuals directly to inform them and provide support." People claiming responsibility for the attack have posted in multiple Telegram groups. Posts seen by The Register include snippets of data that appear to belong to high-profile individuals, including CEOs, sports professionals, and performing artists. The posters are also threatening to release "more and more data every day until Revolut pays for leaking their customers," and are demanding 10,000 Bitcoin as a ransom, equivalent to more than $782 million. Revolut did not comment on the alleged ransom demands when asked. The company currently serves more than 80 million personal customers globally, as well as more than 800,000 businesses. Its co-founder and CEO, Nik Storonsky, has hinted at taking the fintech public, but not before 2028, with a target valuation of around $200 billion. ยฎ
A former AT&T retail worker who used his system access to hijack customers' phone numbers for cybercriminals has been sentenced to 16 months in federal prison. Kenneth Carter, 44, carried out the SIM swaps at a store in Portland, Oregon, , allowing the criminals to intercept authentication codes and raid victims' bank accounts. Court documents show that Carter worked with at least three other people in the scheme, which ran between May 2018 and November 2019, and caused nearly $600,000 in intended losses. Co-conspirator One, described in court documents as the operation's main "hacker," identified victims with online bank accounts, gathered their personal data, and sent it to Carter, who could reassign their phone numbers. Carter abused his access to AT&T's systems to transfer victims' phone numbers to devices controlled by the other criminals. His role was described as "instrumental to the scheme." Co-conspirator Two and Co-conspirator Three would walk into the store and impersonate the victim whose number they planned to SIM-swap, and Carter would reassign the number to a phone they controlled โ usually a "cheap flip phone." Once the swap was complete, the criminals could use the flip phone to intercept SMS-based 2FA codes and password reset messages, take over the victim's bank account, and steal funds. The intercepted codes were relayed to Co-conspirator One, who used them to access the victims' bank accounts. Court documents also refer to "an unnamed family member" who held a minor role in the scheme. They were described as someone "who occasionally passed along the two-step authentication codes" to Co-conspirator One. According to the Justice Department, three victims incurred combined intended losses of $593,963.77, and Carter admitted carrying out additional unauthorized SIM swaps. Carter's plea agreement [PDF] included details of three SIM swap attacks he helped execute. Only one victim suffered an actual loss: $99,528.33 transferred to a Portuguese bank account. The conspirators attempted to transfer $247,652.74 and $246,782.70 from the other two victims, but the banks' fraud controls blocked both transactions. Prosecutors said Carter was paid between $1,000 and $2,000 per swap, although he maintained that he earned less than $4,000 in total. Law enforcement raided Carter's residence in November 2019, finding copies of the personal data provided to him to carry out the SIM swaps, including the Social Security number of the one victim whose money was successfully stolen. AT&T terminated Carter's employment at an unspecified date in 2019. He pleaded guilty on March 24, 2026, to conspiracy to commit wire fraud and bank fraud. In a letter to United States District Judge Stanley Blumenfeld, Jr., Carter described his offending as "a one-off situation that truly was a mistake." He explained that he takes care of his mother-in-law, who spends much of her time in a hospital bed located in the family living room, and two daughters, one of whom has schizophrenia. Carter claimed that he was "propositioned by my in-law cousin with an opportunity for me to make a little extra money for my family." "I was told I wouldn't have to do anything but do my job," he added. "So, I was under the impression that this was a harmless act. As far as I knew at the time, I was never a part of a ring, nor was this an out-of-state matter. "My incident was isolated to just Portland, OR, and the incident occurred while I was employed by AT&T. I later learned that what I found myself a part of was criminal, and I also learned after the fact the severity of what my co-conspirators were doing with the flip phones I sold under customer accounts." Federal prosecutors were unmoved by Carter's letter. In their response [PDF], US attorneys argued that Carter had not provided enough evidence to show he was unaware of the criminal activity's scope or nature, or that he was less culpable than the "hacker" who coordinated the operation. In addition to the 16-month sentence, Judge Blumenfeld, Jr. ordered Carter to pay $99,528 in restitution. ยฎ
A Ukrainian lawyer who wound up coding malware for the Conti ransomware gang has been sentenced to four years in a US prison. Oleksii Oleksiyovych Lytvynenko, 44, pleaded guilty in June to conspiracy to commit wire fraud over his role in Conti, the Russia-linked ransomware operation associated with more than 1,000 victims and at least $150 million in ransom payments. Lytvynenko took an unusual route into the ransomware business. The Ukrainian national, who later lived in Cork, Ireland, trained as a lawyer before joining Conti as an intruder and developer. According to his plea agreement [PDF], Lytvynenko operated under the handle "henry" and joined a team run by another Conti conspirator known as "silver" or "buza." He was recruited to help with coding and directed to work on a malware loader โ software designed to get other malicious code running on a victim's machine. Prosecutors said his Google account showed he had also been doing some homework. Investigators found books and videos about malware and hacking alongside Conti malware, ransom notes, and stolen victim data. Prosecutors said he also used Google and ZoomInfo to research potential targets. Lytvynenko wasn't confined to writing code, according to the filing. Evidence from his online accounts showed that he possessed data stolen from eight US victims and four overseas, with the eight American victims reporting more than $1.5 million in losses. Court documents identify several Bitcoin transfers tied to his Conti work, including 0.4 BTC worth $25,042 that prosecutors traced back to one of his victims. He has been ordered to forfeit the same amount. Conti disbanded in 2022 after its internal chats and source code were leaked following the gang's public support for Russia's invasion of Ukraine. Lytvynenko apparently didn't take that as his cue to find another line of work. When Gardaรญ turned up at his County Cork home in July 2023, they said they found his laptop open, Cobalt Strike running and a Rocket.Chat session connected over Tor. Prosecutors said evidence recovered from the machine showed that his involvement in ransomware activity had continued after Conti disbanded. Lytvynenko was extradited from Ireland to the US in October 2025. The Justice Department says Conti attacked organizations across 47 US states, the District of Columbia, Puerto Rico, and 31 foreign countries between 2020 and 2022. By January 2022, the FBI estimated that victim payouts associated with Conti exceeded $150 million. Lytvynenko will now have four years to contemplate a career change. ยฎ
Crypto hardware wallet maker Trezor says the third-party email service provider it uses to send newsletters has been breached, and customers are now being sent phishing messages. There is good and bad news. The good news is that the emails appear easy to spot. They are not bespoke to each recipient and resemble a spray-and-pray campaign rather than sophisticated targeting that uses customer-specific data to enhance the email's perceived authenticity. All known examples of the scam email are titled "Critical Security Alert: STM32 Entropy Vulnerability," and the body explains that an estimated one in four Trezor devices are affected by a "hardware factory defect." The email warns customers that wallet seeds are exposed to brute-force attacks due to "insufficient randomness" and a "critically low 40-bit entropy." The email asks recipients to share their wallet backups. Trezor said: "Do not click it or interact with it. Never enter your wallet backup anywhere. Always confirm every action with your Trezor physically." The bad news is that because the attackers allegedly compromised the legitimate email provider, the messages can pass authentication checks and bypass some of the usual protections deployed by receiving email services. According to those who have shared copies of the emails, they appear to be sent from "mailing@trezor.io." Trezor has issued the warning across its social media channels and Trezor Suite, the companion app for its hardware wallets. The Register asked Trezor for more information. The third party email provider Brevo โ formerly known as Sendinblue โ said in a statement that a "security incident" had "allowed an attacker to access 120 Brevo accounts." It added that the "bad actor used the access to send phishing emails to the client's contactbase," and promised a "full post mortem later today." Swiss hardware wallet maker BitBox also appears to be affected, having shared an image of an email nearly identical to the one targeting Trezor's newsletter subscribers. The email similarly warns of entropy weaknesses affecting BitBox devices, although it is titled slightly differently: "Critical Security Alert: Microcontroller Entropy Bug Identified." The company said on X: "Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised. "Multiple other Bitcoin companies got targeted as well, and it appears that we all share the same newsletter provider. "We sent out a phishing warning to all our newsletter subscribers, contacted the provider and reported the phishing domains. Most of the phishing links appear to have been taken down already. "We are still actively investigating this situation and will update you once we know more." Crypto tax and portfolio-tracking company CoinTracking also disclosed the compromise of its third-party email provider, which it named as Brevo, around the same time as Trezor and BitBox. CoinTracking shared a copy of the phishing email targeting its users and, since it does not offer hardware wallets, the message uses a different lure, asking customers to follow a link to refresh their API keys. Tough times in Trezorland The latest security snafu comes less than a month after Trezor announced that thousands of customers' details had been compromised following a breach at logistics partner ShipMonk. The hardware vendor initially estimated that around 13,000 people were affected. Those who ordered Trezor products between May 10 and August 8 had their names, email addresses, phone numbers, and shipping addresses breached. Compounding the problem for a company whose brand centers on security, Trezor confirmed on September 4 that the total number of affected customers had risen to 80,000. Trezor said ShipMonk later informed it that an additional 67,000 US customers who purchased products between November 2019 and August 2021 were affected. "Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications," said Trezor. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems." ยฎ
The ringleader of a sprawling cybercrime operation has pleaded guilty in the US after helping to steal and launder hundreds of millions of dollars in cryptocurrency. Malone Lam, 22, a Singaporean national and Miami resident, spearheaded the scheme to steal cryptocurrency from wealthy individuals between October 2023 and May 2025. He first visited the US in 2023 after meeting two of the group's earliest alleged members โ Jeandiel Serrano and Veer Chetal โ while playing Minecraft online. Lam performed various functions within the group, although court documents [PDF] identify victim selection and social engineering support as his principal roles. The ringleader was responsible for obtaining databases of high-net-worth individuals who had cryptocurrency holdings to inform the group's targeting. He would also trigger account access notifications on victims' devices to convince them that their accounts were under attack. He was also involved in laundering the proceeds through exchanges that, according to court documents, had lax KYC requirements. Other group members carried out the social engineering calls, claiming to represent Google, Yahoo, Coinbase, Gemini (the crypto exchange, not the AI chatbot), and other online platforms. Their job was to convince victims to surrender personal information and "access codes" that could be used to access their accounts. Once they secured access, Lam's crew would look for cryptocurrency accounts, seed phrases, and passwords they could use to steal victims' assets. In most cases, social engineering techniques were enough to meet the thieves' goals, although in one case involving a victim who stored their holdings in a hardware wallet, Lam's gang arranged for Marlon Ferro to physically break into a house and steal it. The Register covered Ferro's sentencing earlier this year. He was brought into Lam's fold when he was just a teenager, tasked with carrying out multiple burglaries across the US when remote social engineering attacks lacked the necessary reach. During the crew's nearly two-year operation, its members stole hundreds of millions of dollars' worth of cryptocurrency. The individual thefts ranged from about $800,000 to tens of millions of dollars, while one victim lost more than $245 million, according to court documents. Lam's crew, allegedly comprising at least 12 individuals, knew how to spend their illicit gains. Prosecutors claim they splurged up to $500,000 on a single evening at a nightclub, dished out handbags worth tens of thousands of dollars to partygoers, and bought luxury clothing and watches priced between $100,000 and $500,000. They rented expensive properties in Miami, Los Angeles, and the Hamptons, chartered private jets, hired a team of private bodyguards, and splashed out on exotic cars, with some worth up to $3.8 million. Lam was arrested at a rented property in Miami on September 18, 2024. His sentencing hearing has not yet been scheduled. The court has set a status hearing for December 8. Lam pleaded guilty to one count of participating in a racketeering conspiracy, an offense carrying a maximum sentence of 20 years in prison. "If you build a cybercrime empire, we will find you, dismantle your operation, and hold you accountable," said US Attorney Jeanine Ferris Pirro. "This defendant led an international network that preyed on victims through deception, invaded their privacy, and stole hundreds of millions of dollars in cryptocurrency. "Working with our partners at the FBI and IRS-CI, we will continue to hunt down the criminals who weaponize technology to steal from innocent people." ยฎ
Security researcher Scott Helme says his analysis supports FulcrumSec's claim that Manchester Airports Group (MAG) exposed privileged API keys in client-side JavaScript. Helme says he reached that conclusion after using information provided by the cyber extortion group to reconstruct how data belonging to roughly 8.8 million MAG customers was allegedly stolen last month. The crooks behind the attack described MAG's security failure as "tragi-comical." They claimed MAG exposed overprivileged API keys for Iterable, a marketing automation platform, in front-end JavaScript served by the websites of MAG's three airports: Manchester, Stansted, and East Midlands. Helme used the Internet Archive's Wayback Machine to retrieve older versions of the JavaScript and found that the three keys first appeared across the airport websites in June and July 2022. The same values remained exposed until August 2026, he said. "Read the timeline the other way round and it's worse," said Helme. "Anyone who looked at that page source on any day between June 2022 and August 2026 could have taken the key. FulcrumSec just happen to be the ones who told us. "There is no way to know, from the outside, who else did, and the honest answer is that MAG can't know either without going back through four years of Iterable API logs, if they even have four years of Iterable API logs." The API keys were not embedded directly in the HTML, Helme explained, but anyone who examined the JavaScript bundles loaded by the sites could find them. This would explain how the vulnerability could go unnoticed by the airport's IT teams for over four years. Helme says the browser-delivered code was using the keys to authorize server-side API operations โ something Iterable's documentation explicitly warns against. The requests should instead have passed through MAG's own servers, where the credentials could be kept secret and access restricted. MAG's alleged exposure of the credentials was not the only issue at play. The keys were vastly overprivileged for their intended job, which was to attribute page clicks to marketing emails, Helme said. The keys had read/write access to core Iterable endpoints, giving anyone who obtained them the ability to access data such as customer profiles, parking and lounge bookings, and Fast Track purchases. Helme said the structure and contents of the stolen data indicated that it had been exported from Iterable. He said he also found that the keys could access endpoints capable of deleting customer records and lists or rewriting profiles. "There's no indication FulcrumSec did any of this, and I'm glad, but they could have just nuked everything from orbit and MAG would have been really screwed," said Helme. "For four whole years, the capability to delete Manchester Airports Group's database was a view-source away. "This wasn't only a confidentiality exposure. It was a colossal integrity and availability exposure too, and MAG just got lucky. How do they now trust any of the data that remains in the database?" When it disclosed the incident, MAG described the cyberattack as "sophisticated" and said it was "a hack, not a lapse." The company declined to comment on Helme's conclusions. MAG is continuing its investigation alongside the Information Commissioner's Office (ICO) and supporting the National Crime Agency with its inquiries. It is understood that MAG maintains it was the victim of a crime and disputes Helme's "no hacking required" characterization. FulcrumSec released the company's data on September 2, a week after MAG confirmed it had refused to pay. According to the ICO, the group's extortion demand was lower than those typically made by cybercriminals. ยฎ
Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking attempts. Fishbrain AB, which says its eponymous app serves more than 20 million anglers, disclosed the August 19 breach to the California Attorney General's Office this week. The unknown perpetrators helped themselves to a trawl of user data, including names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, password hashes, and salts. "Fishbrain passwords were not stored in plaintext; however, Fishbrain has determined that the compromised password hashes for some users may be susceptible to being decoded," the company said in its disclosure [PDF]. It added: "If you use your Fishbrain password for any other online accounts, you should promptly update those passwords and any associated security questions or answers. "You should also take other appropriate steps to protect any online accounts that use the same username or email address and password combination. We recommend using a strong, unique password for each of your accounts." With the hashes and salts in hand, attackers can make password guesses using their own hardware until they potentially recover the original credentials. Whether those attempts succeed depends on the strength of each password and the hashing algorithm Fishbrain used, which the company did not disclose. Fishbrain did not comment on the scale of the breach or how many of its claimed 20 million-plus users were affected. The Register asked Fishbrain for more information. After discovering the intrusion and conducting an initial forensic investigation, Fishbrain patched the vulnerability and reset every user's password. Customers must create a new one the next time they log in. Fishbrain also said it "restricted access to the affected environment," strengthened its security controls, and initiated "a broader review of our data security measures" while the investigation continues. Fisherfolk should also keep an eye out for phisherfolk using the stolen personal data to bait follow-on attacks. ยฎ
International law enforcement agencies, working with CrowdStrike and Shadowserver Foundation, have disrupted Sality, a 23-year-old peer-to-peer botnet used to deliver malware to more than 15,000 machines worldwide. The botnet has operated since 2003 and distributed all types of malicious code to victims, spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. For the past eight years, Salityโs primary payload has been EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses, then silently replaces them with attacker-controlled addresses. When a victim copies a bitcoin or ethereum address to make a payment, the malware redirects funds into the criminalsโ wallets. CrowdStrike estimates Sality's operator stole at least $150,000 in cryptocurrency using EggJagger alone. On Monday, CrowdStrike's Counter Adversary Operations team, working with international law enforcement agencies and industry partners, disrupted Sality by executing a peer-to-peer sinkhole operation. This operation isolated infected machines, which broke the criminal operatorโs ability to communicate with devices on its network. Once isolated, the bots can no longer receive payload download instructions or direct payload transfers, effectively breaking the botnet. โIn practice, the operation targeted the data structure at the heart of every bot's network awareness: its peer list,โ CrowdStrike Counter Adversary Operations team said in a technical writeup about the takedown. Each Sality bot maintains a list of known super peers โ publicly reachable infected machines that form the backbone of the P2P network. Every 40 minutes, the bots check to see if their peers are still online. Peers that fail to respond are purged from the network. The counterattack took advantage of this by removing legitimate super peers in each botโs peer list, continually isolating more infected machines in the network, and inserting purpose-built sinkhole entries into peer lists. That approach gave police and cyber operatives visibility into the operationโs progress and helped them notify victims. In addition to the sinkhole operation, the US Justice Department, FBI, and Department of Defense Office of Inspector Generalโs Defense Criminal Investigative Service seized Sality-linked domains in the US. Meanwhile, international law enforcement in Bulgaria, Hungary, and Romania took action against additional Sality-linked domains hosted in Europe. Meanwhile, the Shadowserver Foundation is working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infections and aid in victim notification and remediation.ยฎ