OBSIDIANPAPER
HBO Max logo with Reddit verified checkmark and malware warning symbols representing the ClickFix malvertising campaign that hijacked the official u/hbomax account to spread info-stealing malware
Tech

100M-Scale Malware Attack via HBO Max Reddit Account

Hackers hijacked the official u/hbomax Reddit account to run 108 malicious ClickFix ads, tricking users into pasting terminal commands that stole passwords, browser data, and cryptocurrency wallets.

||6 min read

In modern digital advertising, a blue checkmark or a verified corporate handle is designed to signal authenticity and safety. However, when threat actors bypass administrative controls to take command of a major brand official ad platform, that built-in consumer trust turns into a high-yield vector for malware distribution. In a major malvertising incident uncovered by cybersecurity researchers at Hudson Rock and ADAMnetworks, attackers successfully hijacked the verified u/hbomax Reddit account.

Over a 48-hour blitz, the compromised account deployed 108 distinct malicious advertisements targeting users across Windows and macOS environments, igniting urgent concerns regarding digital privacy, brand credential security, and ad-network auditing. The attack represents part of a broader, cross-platform delivery pipeline dubbed PasteSwitch, designed to exfiltrate sensitive local data, browser profiles, and cryptocurrency assets.

The ClickFix Social Engineering Loop | Tricking Users Into Hacking Themselves

Rather than exploiting complex browser zero-day vulnerabilities, the attackers relied on ClickFix, one of the fastest-growing social engineering tactics. When users clicked the verified u/hbomax ads, they were redirected to convincing landing domains such as hbomaxx.us or hbomaxx.app that mimicked the official streaming service branding. The sites offered a native desktop application for macOS or specialized system updates.

Upon clicking Download, no file transferred. Instead, a prompt popped up instructing the visitor to copy a string of code and paste it directly into their operating system command interface, macOS Terminal or Windows PowerShell or Run, under the guise of verifying a CAPTCHA or completing installation. Because the user executes the command manually, traditional endpoint security tools and browser download warnings fail to flag the initial activity. Once executed, the scripts deployed infostealers like MacSync and Amatera, which immediately harvested browser credentials, Apple Notes, session tokens, and recovery phrases from local crypto wallets.

Digital Privacy Concerns | The Ad Infrastructure Vulnerability

The hijacking of a major entertainment brand account highlights severe structural vulnerabilities in corporate identity management and self-serve ad networks. Advertising security relies heavily on reputation scores. Because u/hbomax was a long-standing, verified corporate account, ad moderation systems allowed newly submitted ad creatives to go live rapidly without triggering high-risk security filters. This blind trust factor is a feature of the advertising ecosystem that attackers have learned to exploit.

Security analysts suspect the breach originated from a compromised session token or credential theft affecting an internal social media manager or agency partner authorized to run campaigns on behalf of Warner Bros. Discovery. Beyond HBO Max branding, the attackers used the account to run ads promoting fake AI software like Codex Craft and disk utilities, maximizing their yield across developer and tech-focused communities before Reddit administrators paused the ad queues.

The incident parallels the broader pattern of AI-enabled cyber threats that have characterized 2026, where attackers leverage automation and social engineering at scale. The ClickFix technique is particularly concerning because it requires no technical exploit, just psychological manipulation, making it accessible to a wide range of threat actors. As cybercriminals increasingly weaponize brand verification and social engineering to bypass perimeter defenses, security experts urge users to maintain strict caution: never copy and paste unknown command-line scripts directly into Terminal or PowerShell, regardless of how legitimate the source domain appears.

wide range of threat actors." type="analysis" source="BleepingComputer, September 2026" sourceUrl="https://www.google.com/search?q=https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/" />

Frequently Asked Questions

Discussion

Comments post live to the OzoneNews Discord server.
Join server β†’

Every comment appears live in our Discord server.

Join to see the full conversation and connect with the community.

Join OzoneNews Discord

Comments sync to our OzoneNews Discord Β· 100M-Scale Malware Attack via HBO Max Reddit Account.

J

Written by

Jackson Yonwang

Editor-in-Chief