Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Cybercriminals have hijacked HBO Max’s official Reddit account to spread malware by pushing malicious ads that trick users into installing information-stealing malware. Over 48 hours, the verified u/hbomax account posted 108 malicious advertisements, some of which impersonated the streaming service while others promoted fake AI tools and developer software.

The attackers used a social engineering technique called ClickFix, where victims are lured into running malicious commands in their operating system’s built-in tools. This tactic is particularly effective as it bypasses many security measures designed to detect malware downloads. The ads prompted users to copy and paste commands into Windows Run or PowerShell on Windows systems, while macOS users were instructed to open Terminal.

The campaign has been linked to a larger operation called PasteSwitch, which targets both Windows and macOS systems. This operation uses a unique approach where attackers supply commands that victims paste into their systems, while the backend switches between campaigns, platforms, payloads, and cryptocurrency theft methods depending on the visitor. The researchers have identified information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications as part of this operation.

The incident was first discovered when a Reddit user spotted an advertisement promoting what appeared to be a native HBO Max application for macOS. However, clicking the download button led users to a convincing fake HBO Max website that instructed them to paste a command into Terminal to install the software. This command used Base64 encoding to obscure its contents and, once decoded, it executed a malicious script from a compromised server.

The malware deployed in this campaign includes MacSync, which steals browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords. Another attack chain established persistence using a directory named .com.apple.accountsd, allowing the malware to enroll infected systems with attacker-controlled servers for further tasks. The researchers have also observed fake cryptocurrency wallet applications designed to steal victims’ wallet recovery phrases.

The campaign has been linked to a larger operation called PasteSwitch, which targets both Windows and macOS systems. This operation uses a unique approach where attackers supply commands that victims paste into their systems, while the backend switches between campaigns, platforms, payloads, and cryptocurrency theft methods depending on the visitor. The researchers have identified information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications as part of this operation.

BleepingComputer contacted HBO and Warner Bros. Discovery with questions about the incident but has not received a response.

In practical terms, this incident highlights the importance of being cautious when interacting with online ads, particularly those that prompt users to execute commands in their operating system’s built-in tools. Users should never run instructions from unknown sources or click on suspicious links or download applications from unverified websites. Always verify the authenticity of advertisements and be wary of any requests for sensitive information or passwords.


Source: Bleeping Computer — 2026-09-14