HomeLatest NewsCyber SecurityHBO Max Reddit account hijacked to spread malware via ClickFix ads

HBO Max Reddit account hijacked to spread malware via ClickFix ads

Security researchers found that hackers compromised HBO Max's verified Reddit account to push 108 malicious advertisements using ClickFix attacks. The campaign targeted Windows and macOS users with information-stealing malware and fake cryptocurrency wallet applications.

Preferred Source of Google

Key Points

  • HBO Max Reddit account compromised to push 108 malicious advertisements over 48 hours
  • ClickFix attacks targeted both Windows and macOS users with information-stealing malware
  • Campaign distributed fake cryptocurrency wallet applications to steal recovery phrases

Hackers compromised HBO Max’s official Reddit account and used it to distribute malicious advertisements that infected and macOS devices with information-stealing malware, security researchers have found.

The verified u/hbomax Reddit account was hijacked and used to launch 108 malicious advertisements over approximately 48 hours, according to analysis by security firms Hudson Rock and ADAMnetworks. The attack used a technique known as ClickFix, a social engineering method that tricks users into copying and pasting malicious commands into their operating system’s command line interface while believing they are fixing an error, verifying a security check or installing legitimate software.

Advertisement
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →

The ClickFix technique has gained popularity among cybercriminals because victims execute the malicious commands themselves using built-in operating system tools, potentially bypassing browser security measures and antivirus software designed to detect conventional malware downloads.

While some advertisements pushed through the HBO Max account impersonated the streaming service, others promoted fake artificial intelligence tools, developer software and macOS system utilities. This allowed the attackers to target a broader audience than just streaming service users, including software developers and users searching for AI applications.

PasteSwitch campaign

Hudson Rock and ADAMnetworks have linked the attack to a larger operation they call PasteSwitch, which targets both Windows and macOS systems. The campaign has been used to distribute information stealers, loaders, cryptocurrency clippers and fake cryptocurrency wallet applications.

Advertisement

The researchers said PasteSwitch refers to the operation’s use of attacker-supplied commands that victims paste into their systems. The attackers’ backend infrastructure switches between campaigns, platforms, payloads and cryptocurrency theft methods depending on who visits the malicious sites.

The campaign was initially discovered after a Reddit user spotted an advertisement posted from the verified HBO Max account promoting what appeared to be a native HBO Max application for macOS. The user reported that the advertisement directed to a website that looked legitimate but instructed visitors to paste a command into their Terminal application to install the software.

One of the fake HBO Max websites used in the campaign was hbomaxx[.]us. Clicking the download button did not download an application but instead displayed instructions telling visitors to open Terminal, the command line interface on macOS, and paste a command. The command used Base64 encoding, a method of obscuring text that converts readable characters into a different format, to hide what it actually executed.

Advertisement

Malware variants

One malware family used in this attack is MacSync, which Hudson Rock said steals browser credentials, Firefox browser profiles, Telegram messaging data, Notes and macOS system passwords. Another attack chain deployed a malware component that establishes persistence using a hidden directory on the infected system. The malware can then connect to attacker-controlled servers to receive additional instructions.

The campaign has also distributed fake Ledger, Trezor Suite and Exodus cryptocurrency wallet applications designed to steal victims’ wallet recovery phrases, the series of words that provide complete access to cryptocurrency holdings.

On Windows systems, the PasteSwitch operation has been observed displaying instructions that cause victims to execute commands using mshta and PowerShell, built-in Windows utilities. Hudson Rock said one Windows attack chain used a file that appeared to be an MP3 audio file but contained hidden instructions. This created a scheduled task, launched PowerShell, disabled ‘s Antimalware Scan Interface (AMSI), a Windows security feature that scans scripts for malicious content, and generated victim-specific infrastructure based on the computer name and username.

Later stages used obfuscated PowerShell commands and shellcode, low-level computer instructions, to load the Amatera Stealer malware directly into the computer’s memory without first saving it to the hard drive, making it harder for security software to detect.

The PasteSwitch operation has also distributed cryptocurrency clipboard hijacking malware, including variants called AnimateClipper and ZigClipper. These monitor the clipboard and replace cryptocurrency wallet addresses copied by users with addresses controlled by the attackers, redirecting cryptocurrency transfers.

Advertisement scope

By the numbers

Key figures from this story
108
malicious advertisements pushed through hijacked account
48 hours
duration of the malicious advertising campaign
40
ads promoting fake HBO Max download sites

The researchers identified the full scope of the campaign run through the compromised Reddit account. They found 40 advertisements pointing to hbomaxx[.]app, 36 promoting a fake AI and developer site at codex-craft[.]com, 15 promoting a fake disk cleaning utility at apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com and six promoting hbomax-macos[.]com.

After the malicious advertisements were reported, a Reddit administrator paused them and referred them to Reddit’s security and safety teams. It remains unclear how the attackers accessed the HBO Max Reddit account or whether any other HBO or Warner Bros Discovery accounts or systems were affected.

Your Questions, Answered

What is ClickFix and how does it work?

ClickFix is a social engineering technique where attackers trick users into copying and pasting malicious commands into their operating system's command line while believing they are fixing an error or installing software. Victims execute the malware themselves using legitimate system tools.

What malware was distributed through the HBO Max Reddit hack?

The campaign distributed MacSync information stealer, Amatera Stealer, cryptocurrency clippers like AnimateClipper and ZigClipper, and fake cryptocurrency wallet applications designed to steal recovery phrases.

How can users protect themselves from ClickFix attacks?

Users should never copy and paste commands from websites into Terminal or PowerShell. Legitimate software never requires manual command line installation. Always download applications from official app stores or verified developer websites.

Were HBO Max user accounts compromised in this attack?

The attack compromised HBO Max's Reddit account used for advertising, not HBO Max subscriber accounts. However, users who clicked the malicious ads and followed the instructions may have had their devices infected with malware.

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

Tech Observer Desk
Tech Observer Desk
Tech Observer Desk at TechObserver.in is a team of technology reporters led by a senior editor who brings latest updates and developments from the world of technology.
Advertisement
- Advertisement -
- Advertisement -

Multi-agent AI platforms market to hit $129 billion by 2035: report

The global market for multi-agent AI platforms is projected to grow from $2.90 billion in 2025 to $129.38 billion by 2035, driven by enterprise demand for autonomous AI systems that coordinate multiple agents to handle complex business tasks.

RELATED ARTICLES