Hackers Hijack HBO Max Reddit Account to Push Malware in ClickFix Ads
A sophisticated cyberattack has seen hackers compromise the official HBO Max Reddit account, using it to spread malicious ads that launched attacks on Windows and macOS devices. The campaign, dubbed PasteSwitch by security researchers, targeted both platforms with a range of malware payloads.
The attack worked by tricking users into copying and pasting malicious commands into their operating system tools, such as Windows Run or PowerShell, under the guise of fixing an error or installing legitimate software. This technique, known as ClickFix, has become increasingly popular among cybercriminals because it allows them to bypass some browser and security software designed to detect malware downloads.
The hackers used the HBO Max account to launch 108 malicious advertisements over a period of approximately 48 hours. While some ads impersonated the streaming service, others promoted fake AI tools, developer software, and macOS utilities. In one instance, users were directed to a convincing fake HBO Max website that offered a native application for download. However, clicking the link instead displayed instructions telling visitors to open Terminal and paste a command to install the software.
Security researchers at Hudson Rock and ADAMnetworks analyzed the campaign and linked it to a larger operation targeting both Windows and macOS systems. The PasteSwitch campaign has been used to distribute information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications. One of the malware families used in this attack is MacSync, which steals browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords.
The researchers note that the attackers’ backend switches between campaigns, platforms, payloads, and crypto theft methods depending on the visitor. This makes it challenging to identify the full extent of the campaign’s reach. HBO and Warner Bros. Discovery have been contacted for comment but have yet to respond.
The PasteSwitch campaign is a prime example of how cybercriminals are becoming increasingly sophisticated in their tactics. As users, it’s essential to remain vigilant when encountering suspicious ads or links, especially on social media platforms like Reddit. Before copying and pasting commands into your operating system tools, verify the source and be cautious of any instructions that seem unusual or overly complex.
In practical terms, this means being wary of ads that promise quick fixes or solutions to complex problems. If you’re unsure about the legitimacy of an ad or link, do not proceed. Instead, visit the official website of the company or service mentioned in the ad and contact their support team directly. By taking these simple precautions, you can significantly reduce your risk of falling victim to such attacks.
Source: Bleeping Computer — 2026-09-14