Key Points
- HBO Max Reddit account compromised to push 108 malicious advertisements over 48 hours
- ClickFix attacks targeted both Windows and macOS users with information-stealing malware
- Campaign distributed fake cryptocurrency wallet applications to steal recovery phrases
Hackers compromised HBO Max’s official Reddit account and used it to distribute malicious advertisements that infected Windows and macOS devices with information-stealing malware, security researchers have found.
The verified u/hbomax Reddit account was hijacked and used to launch 108 malicious advertisements over approximately 48 hours, according to analysis by security firms Hudson Rock and ADAMnetworks. The attack used a technique known as ClickFix, a social engineering method that tricks users into copying and pasting malicious commands into their operating system’s command line interface while believing they are fixing an error, verifying a security check or installing legitimate software.
The ClickFix technique has gained popularity among cybercriminals because victims execute the malicious commands themselves using built-in operating system tools, potentially bypassing browser security measures and antivirus software designed to detect conventional malware downloads.
While some advertisements pushed through the HBO Max account impersonated the streaming service, others promoted fake artificial intelligence tools, developer software and macOS system utilities. This allowed the attackers to target a broader audience than just streaming service users, including software developers and users searching for AI applications.
PasteSwitch campaign
Hudson Rock and ADAMnetworks have linked the attack to a larger operation they call PasteSwitch, which targets both Windows and macOS systems. The campaign has been used to distribute information stealers, loaders, cryptocurrency clippers and fake cryptocurrency wallet applications.
The researchers said PasteSwitch refers to the operation’s use of attacker-supplied commands that victims paste into their systems. The attackers’ backend infrastructure switches between campaigns, platforms, payloads and cryptocurrency theft methods depending on who visits the malicious sites.
The campaign was initially discovered after a Reddit user spotted an advertisement posted from the verified HBO Max account promoting what appeared to be a native HBO Max application for macOS. The user reported that the advertisement directed to a website that looked legitimate but instructed visitors to paste a command into their Terminal application to install the software.
One of the fake HBO Max websites used in the campaign was hbomaxx[.]us. Clicking the download button did not download an application but instead displayed instructions telling visitors to open Terminal, the command line interface on macOS, and paste a command. The command used Base64 encoding, a method of obscuring text that converts readable characters into a different format, to hide what it actually executed.
Malware variants
One malware family used in this attack is MacSync, which Hudson Rock said steals browser credentials, Firefox browser profiles, Telegram messaging data, Apple Notes and macOS system passwords. Another attack chain deployed a malware component that establishes persistence using a hidden directory on the infected system. The malware can then connect to attacker-controlled servers to receive additional instructions.
The campaign has also distributed fake Ledger, Trezor Suite and Exodus cryptocurrency wallet applications designed to steal victims’ wallet recovery phrases, the series of words that provide complete access to cryptocurrency holdings.
On Windows systems, the PasteSwitch operation has been observed displaying instructions that cause victims to execute commands using mshta and PowerShell, built-in Windows utilities. Hudson Rock said one Windows attack chain used a file that appeared to be an MP3 audio file but contained hidden instructions. This created a scheduled task, launched PowerShell, disabled Microsoft‘s Antimalware Scan Interface (AMSI), a Windows security feature that scans scripts for malicious content, and generated victim-specific infrastructure based on the computer name and username.
Later stages used obfuscated PowerShell commands and shellcode, low-level computer instructions, to load the Amatera Stealer malware directly into the computer’s memory without first saving it to the hard drive, making it harder for security software to detect.
The PasteSwitch operation has also distributed cryptocurrency clipboard hijacking malware, including variants called AnimateClipper and ZigClipper. These monitor the clipboard and replace cryptocurrency wallet addresses copied by users with addresses controlled by the attackers, redirecting cryptocurrency transfers.
Advertisement scope
By the numbers
Key figures from this story- 108
- malicious advertisements pushed through hijacked account
- 48 hours
- duration of the malicious advertising campaign
- 40
- ads promoting fake HBO Max download sites
The researchers identified the full scope of the advertising campaign run through the compromised Reddit account. They found 40 advertisements pointing to hbomaxx[.]app, 36 promoting a fake AI and developer site at codex-craft[.]com, 15 promoting a fake disk cleaning utility at apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com and six promoting hbomax-macos[.]com.
After the malicious advertisements were reported, a Reddit administrator paused them and referred them to Reddit’s security and safety teams. It remains unclear how the attackers accessed the HBO Max Reddit account or whether any other HBO or Warner Bros Discovery accounts or systems were affected.
Your Questions, Answered
What is ClickFix and how does it work?
ClickFix is a social engineering technique where attackers trick users into copying and pasting malicious commands into their operating system's command line while believing they are fixing an error or installing software. Victims execute the malware themselves using legitimate system tools.
What malware was distributed through the HBO Max Reddit hack?
The campaign distributed MacSync information stealer, Amatera Stealer, cryptocurrency clippers like AnimateClipper and ZigClipper, and fake cryptocurrency wallet applications designed to steal recovery phrases.
How can users protect themselves from ClickFix attacks?
Users should never copy and paste commands from websites into Terminal or PowerShell. Legitimate software never requires manual command line installation. Always download applications from official app stores or verified developer websites.
Were HBO Max user accounts compromised in this attack?
The attack compromised HBO Max's Reddit account used for advertising, not HBO Max subscriber accounts. However, users who clicked the malicious ads and followed the instructions may have had their devices infected with malware.

