DKDKCISSPSearch
Cyber Attacks

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.

DKCISSP News DeskBleepingComputer15 Sept 2026, 12:04 am
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Image courtesy of BleepingComputer. Original report
DKCISSP REPORT

Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.

The ads used a social engineering technique known as ClickFix, which tricks users into copying and pasting malicious commands into Windows Run, PowerShell, or macOS Terminal while pretending to fix an error, verify a CAPTCHA, or install legitimate software.

The type of attack has become increasingly popular among cybercriminals because victims run the malicious commands themselves using legitimate operating system tools, potentially bypassing some browser and security software designed to detect malware downloads.

Hudson Rock and ADAMnetworks have linked the attack to a larger campaign they call PasteSwitch, which targets both Windows and macOS systems and has been used to distribute information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications.

The researchers say PasteSwitch refers to the operation's use of attacker-supplied commands that victims paste into their systems, while the attackers' backend switches between campaigns, platforms, payloads, and crypto theft methods depending on the visitor.

Discovery with questions about the incident but has not received a response.

The user is verified and appears to have posted many times in the official HBO Max subreddits," warned the user .

Having checked, this downloads an executable with other capabilities for account compromise (obviously all done in a full sandbox - inspecting the output only, not running anything)." One of the fake HBO Max sites used in the campaign was hbomaxx[.]us.

Clicking these opens up the classic infostealer/clickfix paste this command to download.

One of the macOS commands BleepingComputer saw in this attack used Base64 encoding to obscure the command it executed.

However, clicking the download button did not download an app, but instead displayed instructions telling visitors to open Terminal and paste a command to install the software.

Once decoded, it contained the following command: Hudson Rock noted ember-bridge[.]com as infrastructure used in September for malware delivery in the PasteSwitch operation.

One malware family used in this attack is MacSync, which Hudson Rock says steals browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords.

Another attack chain deployed which establishes persistence using a directory named .com.apple.accountsd.

What happened

Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.

The ads used a social engineering technique known as ClickFix, which tricks users into copying and pasting malicious commands into Windows Run, PowerShell, or macOS Terminal while pretending to fix an error, verify a CAPTCHA, or install legitimate software.

The type of attack has become increasingly popular among cybercriminals because victims run the malicious commands themselves using legitimate operating system tools, potentially bypassing some browser and security software designed to detect malware downloads.

What changed

Hudson Rock and ADAMnetworks have linked the attack to a larger campaign they call PasteSwitch, which targets both Windows and macOS systems and has been used to distribute information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications.

The researchers say PasteSwitch refers to the operation's use of attacker-supplied commands that victims paste into their systems, while the attackers' backend switches between campaigns, platforms, payloads, and crypto theft methods depending on the visitor.

Discovery with questions about the incident but has not received a response.

Who is affected

The user is verified and appears to have posted many times in the official HBO Max subreddits," warned the user .

Having checked, this downloads an executable with other capabilities for account compromise (obviously all done in a full sandbox - inspecting the output only, not running anything)." One of the fake HBO Max sites used in the campaign was hbomaxx[.]us.

Why it matters

Clicking these opens up the classic infostealer/clickfix paste this command to download.

One of the macOS commands BleepingComputer saw in this attack used Base64 encoding to obscure the command it executed.

Technical details

However, clicking the download button did not download an app, but instead displayed instructions telling visitors to open Terminal and paste a command to install the software.

Once decoded, it contained the following command: Hudson Rock noted ember-bridge[.]com as infrastructure used in September for malware delivery in the PasteSwitch operation.

One malware family used in this attack is MacSync, which Hudson Rock says steals browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords.

Response

Another attack chain deployed which establishes persistence using a directory named .com.apple.accountsd.

Hudson Rock says one Windows attack chain used an MP3/HTA polyglot to create a scheduled task, launch 32-bit PowerShell, disable Microsoft's Antimalware Scan Interface (AMSI), and generate victim-specific infrastructure based on the computer name and username.

What security teams should do

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

"I was browsing Reddit and saw an ad displaying u/hbomax as the author - this advertised a macOS HBO Max app which I'd not heard of and was interested in.

What remains unknown

It remains unclear how the attackers accessed the HBO Max Reddit account or whether any other HBO or Warner Bros.

Attribution

BleepingComputer: Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN CYBER ATTACKS

More cybersecurity reporting

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix LuresThe Hacker News · 30 Sept 2026, 9:22 pmRatHat's Evolving C2 Panel Points to Malware-as-a-Service Model - Infosecurity MagazineInfosecurity Magazine · 29 Sept 2026, 8:00 pmMicrosoft Warns NeedyMantis Malware Enables Persistent Network AccessInfosecurity Magazine · 29 Sept 2026, 7:00 pmBitget Says Suspected North Korean Hackers Stole $351.6M After Backend CompromiseThe Hacker News · 26 Sept 2026, 1:39 pm