In modern digital advertising, a blue checkmark or a verified corporate handle is designed to signal authenticity and safety. However, when threat actors bypass administrative controls to take command of a major brand official ad platform, that built-in consumer trust turns into a high-yield vector for malware distribution. In a major malvertising incident uncovered by cybersecurity researchers at Hudson Rock and ADAMnetworks, attackers successfully hijacked the verified u/hbomax Reddit account.
Over a 48-hour blitz, the compromised account deployed 108 distinct malicious advertisements targeting users across Windows and macOS environments, igniting urgent concerns regarding digital privacy, brand credential security, and ad-network auditing. The attack represents part of a broader, cross-platform delivery pipeline dubbed PasteSwitch, designed to exfiltrate sensitive local data, browser profiles, and cryptocurrency assets.
The ClickFix Social Engineering Loop | Tricking Users Into Hacking Themselves
Rather than exploiting complex browser zero-day vulnerabilities, the attackers relied on ClickFix, one of the fastest-growing social engineering tactics. When users clicked the verified u/hbomax ads, they were redirected to convincing landing domains such as hbomaxx.us or hbomaxx.app that mimicked the official streaming service branding. The sites offered a native desktop application for macOS or specialized system updates.
Upon clicking Download, no file transferred. Instead, a prompt popped up instructing the visitor to copy a string of code and paste it directly into their operating system command interface, macOS Terminal or Windows PowerShell or Run, under the guise of verifying a CAPTCHA or completing installation. Because the user executes the command manually, traditional endpoint security tools and browser download warnings fail to flag the initial activity. Once executed, the scripts deployed infostealers like MacSync and Amatera, which immediately harvested browser credentials, Apple Notes, session tokens, and recovery phrases from local crypto wallets.
Digital Privacy Concerns | The Ad Infrastructure Vulnerability
The hijacking of a major entertainment brand account highlights severe structural vulnerabilities in corporate identity management and self-serve ad networks. Advertising security relies heavily on reputation scores. Because u/hbomax was a long-standing, verified corporate account, ad moderation systems allowed newly submitted ad creatives to go live rapidly without triggering high-risk security filters. This blind trust factor is a feature of the advertising ecosystem that attackers have learned to exploit.
Security analysts suspect the breach originated from a compromised session token or credential theft affecting an internal social media manager or agency partner authorized to run campaigns on behalf of Warner Bros. Discovery. Beyond HBO Max branding, the attackers used the account to run ads promoting fake AI software like Codex Craft and disk utilities, maximizing their yield across developer and tech-focused communities before Reddit administrators paused the ad queues.
The incident parallels the broader pattern of AI-enabled cyber threats that have characterized 2026, where attackers leverage automation and social engineering at scale. The ClickFix technique is particularly concerning because it requires no technical exploit, just psychological manipulation, making it accessible to a wide range of threat actors. As cybercriminals increasingly weaponize brand verification and social engineering to bypass perimeter defenses, security experts urge users to maintain strict caution: never copy and paste unknown command-line scripts directly into Terminal or PowerShell, regardless of how legitimate the source domain appears.