Last seven days
- First activity
- Sep 25, 2026
- Last activity
- Sep 25, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
PasteSwitch is a cross-platform malvertising and ClickFix malware-delivery operation targeting macOS and Windows users.
Profile source: Mallory opens in a new tabPasteSwitch
PasteSwitch is a cross-platform malvertising and ClickFix malware-delivery operation targeting macOS and Windows users. It abuses trusted advertising distribution channels, including a compromised verified social-media advertising account, to promote counterfeit streaming, AI/developer-tool, disk-utility, and cryptocurrency-wallet software. Victims are directed to fraudulent landing pages and socially engineered to paste attacker-supplied commands into macOS Terminal or Windows execution dialogs, causing attacker-controlled code to run without relying on a software vulnerability.
The operation dynamically selects lures, payloads, and monetization paths based on the victim environment. Its macOS branches have delivered MacSync, Atomic macOS Stealer-related helpers, and fraudulent wallet applications designed to collect browser credentials and data, macOS passwords, messaging-application data, notes, and cryptocurrency recovery phrases. Windows branches have used InstallFix and Amatera Stealer, including obfuscated in-memory execution, scheduled-task creation, and attempts to impair AMSI. PasteSwitch also distributes the AnimateClipper and ZigClipper cryptocurrency clippers, which monitor the clipboard and replace copied cryptocurrency-wallet addresses with attacker-controlled addresses. The clipper components use blockchain smart contracts as mutable command-and-control dead drops. PasteSwitch is tracked as an operation rather than a single malware family; no public attribution to a specific threat actor is established.
C2 tracking
Derp observations, rolling seven-day window
Reporting
Attackers compromised the verified Reddit account u/hbomax and used it to run 108 malicious advertisements over roughly 48 hours. The ads impersonated HBO Max, AI-development tools, and macOS utilities, directing targets into a ClickFix campaign researchers call PasteSwitch that persuaded victims to copy and execute commands in a terminal or Windows Run dialog. The copied commands selected payloads by operating system: macOS victims received MacSync and AMOS Helper stealers, while a Windows InstallFix chain loaded Amatera Stealer in memory. The campaign also deployed fake cryptocurrency wallets and crypto clippers, using direct-to-IP TLS communications and Binance Smart Chain smart contracts to rotate clipper command-and-control domains. Reddit paused the malicious ads and began an internal investigation to secure the compromised account.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.