Verified Account, Malicious Ads
Attackers compromised the official, verified HBO Max account on Reddit and used it to run 108 malicious advertisements over roughly 48 hours, targeting both Windows and macOS users with information-stealing malware. It remains unclear how the attackers gained access to the account, or whether any other HBO or Warner Bros. Discovery accounts and systems were affected.
The ClickFix Lure
The campaign relied on ClickFix, a social engineering technique that tricks victims into copying and pasting attacker-supplied commands into the Windows Run dialog, PowerShell, or the macOS Terminal — typically while posing as a CAPTCHA verification, an error fix, or a legitimate software installer. Because the victim executes the command themselves using trusted, built-in system tools, ClickFix payloads often slip past security controls that focus on file downloads or browser exploits.
Payloads Delivered
Researchers tracking the operation — dubbed PasteSwitch — identified multiple distinct payloads pushed through the hijacked account's ads:
| Payload | Function |
|---|---|
| MacSync | Steals browser credentials, Firefox profiles, Telegram data, Apple Notes, and saved passwords |
| AMOS Helper | Establishes persistence and fetches follow-on tasks from the attacker |
| Amatera Stealer | Loaded directly into memory to evade disk-based detection |
| Fake crypto wallet apps | Clones of Ledger, Trezor, and Exodus used for credential/seed theft |
| AnimateClipper / ZigClipper | Clipboard hijackers that swap copied cryptocurrency addresses |
Response and Takedown
After the malicious ads were reported, a Reddit administrator paused them and escalated the incident to Reddit's Security and Safety teams. The incident occurred in September 2026.
Why This Matters
A verified, high-follower brand account is a high-trust distribution channel — victims are far less likely to question an ad or post coming from what appears to be HBO Max's own presence. Combined with ClickFix's abuse of legitimate OS tooling, the campaign illustrates how attackers increasingly favor trust hijacking and living-off-the-land execution over traditional malicious downloads.
Protective Measures
- Never paste commands into Run, PowerShell, or Terminal from a website prompt, CAPTCHA, or ad — no legitimate fix requires this
- Verify software downloads only from official vendor sites or app stores, never from ad links
- Be skeptical of "verified" accounts — compromise of a legitimate account does not guarantee the safety of its content
- Use a password manager and hardware-backed browser credential storage to limit what a stealer can exfiltrate
- Monitor clipboard-hijacking behavior if you regularly transact in cryptocurrency — verify addresses before sending funds