Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2831+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Hackers Hijack HBO Max Reddit Account to Push ClickFix Malware Ads
Hackers Hijack HBO Max Reddit Account to Push ClickFix Malware Ads
NEWS

Hackers Hijack HBO Max Reddit Account to Push ClickFix Malware Ads

Attackers took over HBO Max's verified Reddit account, running 108 malicious ads over 48 hours that used ClickFix lures to infect Windows...

Dylan H.

News Desk

September 14, 2026
3 min read

Verified Account, Malicious Ads

Attackers compromised the official, verified HBO Max account on Reddit and used it to run 108 malicious advertisements over roughly 48 hours, targeting both Windows and macOS users with information-stealing malware. It remains unclear how the attackers gained access to the account, or whether any other HBO or Warner Bros. Discovery accounts and systems were affected.


The ClickFix Lure

The campaign relied on ClickFix, a social engineering technique that tricks victims into copying and pasting attacker-supplied commands into the Windows Run dialog, PowerShell, or the macOS Terminal — typically while posing as a CAPTCHA verification, an error fix, or a legitimate software installer. Because the victim executes the command themselves using trusted, built-in system tools, ClickFix payloads often slip past security controls that focus on file downloads or browser exploits.


Payloads Delivered

Researchers tracking the operation — dubbed PasteSwitch — identified multiple distinct payloads pushed through the hijacked account's ads:

PayloadFunction
MacSyncSteals browser credentials, Firefox profiles, Telegram data, Apple Notes, and saved passwords
AMOS HelperEstablishes persistence and fetches follow-on tasks from the attacker
Amatera StealerLoaded directly into memory to evade disk-based detection
Fake crypto wallet appsClones of Ledger, Trezor, and Exodus used for credential/seed theft
AnimateClipper / ZigClipperClipboard hijackers that swap copied cryptocurrency addresses

Response and Takedown

After the malicious ads were reported, a Reddit administrator paused them and escalated the incident to Reddit's Security and Safety teams. The incident occurred in September 2026.


Why This Matters

A verified, high-follower brand account is a high-trust distribution channel — victims are far less likely to question an ad or post coming from what appears to be HBO Max's own presence. Combined with ClickFix's abuse of legitimate OS tooling, the campaign illustrates how attackers increasingly favor trust hijacking and living-off-the-land execution over traditional malicious downloads.


Protective Measures

  1. Never paste commands into Run, PowerShell, or Terminal from a website prompt, CAPTCHA, or ad — no legitimate fix requires this
  2. Verify software downloads only from official vendor sites or app stores, never from ad links
  3. Be skeptical of "verified" accounts — compromise of a legitimate account does not guarantee the safety of its content
  4. Use a password manager and hardware-backed browser credential storage to limit what a stealer can exfiltrate
  5. Monitor clipboard-hijacking behavior if you regularly transact in cryptocurrency — verify addresses before sending funds

References

  • BleepingComputer — Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Related Reading

  • Hackers Target Exposed Vite Dev Servers to Steal AWS, Azure Secrets
  • Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks
#Malware#ClickFix#Social Engineering#Reddit#Windows#macOS

Related Articles

Claude AI Artifacts Abused to Distribute macOS Infostealer

Threat actors are abusing publicly shared Claude AI artifacts and Google Ads to deliver the MacSync infostealer to macOS users through ClickFix social...

3 min read

Hackers Abuse Google Ads and Claude.ai Chats to Push Mac

Attackers are running a sophisticated malvertising campaign that hijacks Google Ads and legitimate Claude.ai shared chat sessions to deliver Mac malware...

4 min read

Steam Forum ClickFix Attacks Infect Gamers with XMRig Cryptominers

Threat actors are hijacking Steam discussion threads to pose as helpful community members, tricking frustrated gamers into running malicious PowerShell...

4 min read
Back to all News