HBO Max’s verified Reddit account hijacked to spread malware

Imported from official source

Cybersecurity Classified by Officially

Researchers at Hudson Rock found that cybercriminals hijacked HBO Max’s verified Reddit account and used it to run 108 malicious ads over roughly 48 hours.

The ads used HBO Max’s trusted corporate account to promote fake AI tools, developer software, and macOS utilities, lowering potential victims’ guards.

Some ads directed users to convincing HBO lookalike sites that claimed to offer a native HBO Max app for macOS or a promotional download. But instead of providing an installer, the sites instructed visitors to open Terminal on their Mac or, on Windows, the Run dialog or PowerShell, and paste in a command.

This is the hallmark of a growing social engineering technique known as ClickFix.

ClickFix attacks disguise malicious instructions as a routine technical step, such as fixing an error, completing a CAPTCHA, verifying that you are human, or installing software. A web page may silently copy a command to the clipboard, then guide the victim through pasting and running it, by which they will infect their own device.

Researchers at ADAMnetworks have dubbed the operation behind the HBO Max ads “PasteSwitch.” Its infrastructure appears to tailor the next stage to the visitor’s device and the lure being used.

Observed macOS payloads included MacSync and AMOS infostealers designed to steal browser credentials and profiles, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases.

Windows users could end up with the Amatera infostealer, which runs in memory. The operation has also been linked to cryptocurrency clipboard hijackers, which monitor copied wallet addresses and replace them with an attacker-controlled address before a transaction is sent.

How to stay safe

Reddit admins paused the ads and opened a security investigation after reports came in, but it is important to remain vigilant. Reportedly, ClickFix was responsible for more than half of all malware loader activity in 2025.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware

Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Malwarebytes — imported from official source
Official source
https://www.malwarebytes.com/blog/feed/index.xml RSS
Imported
September 20, 2026 19:52
Versions
1 recorded
Identity
https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacke...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.