Security · September 20, 2026
Also published in Italiano
Hackers hijack HBO Max Reddit account to spread ClickFix ads
Attackers breached the official HBO Max Reddit account and used it to post 108 malicious ads that directed users to ClickFix pages. The ads targeted Windows and macOS users and delivered malware. Researchers from Hudson Rock and ADAMnetworks identified the campaign as PasteSwitch. The attackers promoted a fake HBO Max macOS app on a site called hbomaxx.us, then tricked victims into running a terminal command that installed the malware.
In macOS the payload included MacSync, AMOS Helper and counterfeit Ledger and Trezor apps that stole crypto keys. In Windows the attackers used mshta and PowerShell to deploy Amatera Stealer and disable security features. The campaign also spread AnimateClipper and ZigClipper which altered crypto addresses. Reddit later removed the ads after user complaints.
It remains unclear how the hackers gained access to the HBO Max account or whether other Warner Bros Discovery systems were compromised.