Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack
Hackers used a compromised HBO Max Reddit account to deliver malware via fake app downloads.
Summary
Threat actors compromised the official HBO Max Reddit account to conduct a malvertising campaign, tracked as PasteSwitch, over a 48-hour period. They pushed 108 malicious ads targeting both macOS and Windows users, promoting a non-existent native macOS HBO Max application. The campaign led users to a fake website that prompted them to download malware, including credential and cryptocurrency stealers, and clipboard replacement tools.
Full text
Hackers compromised the official HBO Max account on Reddit and used it in a malvertising campaign leading to a ClickFix landing page. During a 48-hour window, the attackers pushed 108 malicious advertisements across five lure groups as part of the campaign, tracked as PasteSwitch. Using the verified u/hbomax account, the threat actors targeted both macOS and Windows users and aggressively promoted a native macOS application for HBO Max, which does not exist. Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also contained a download button. “The download button opened a ClickFix prompt that told the visitor to copy a command, open Terminal, paste the command, and run it. This transferred execution from the browser to a trusted system utility under the victim’s control,” ADAMnetworks explains. On macOS, the attack relied on curl | zsh commands to deliver malware such as MacSync, AMOS Helper, fake wallet applications, and other malicious code to steal users’ information, including their credentials, messages, browser information, and cryptocurrency wallet information, and gain persistent access to their machines.Advertisement. Scroll to continue reading. On Windows, the attack relied on MSHTA and PowerShell to deliver the Amatera Stealer and achieve persistence. Configured for manual credential validation, the malware would bypass network telemetry by spoofing Facebook connections to hide its command-and-control (C&C) communication. The PasteSwitch campaign also used AnimateClipper and ZigClipper as persistent clipboard replacement tools to swap cryptocurrency addresses when users attempted to make a transaction, HudsonRock notes. According to the security firms, the clipboard stealers use a C&C hosted on the blockchain. The infrastructure was likely set up over a year ago and has been used in attacks since early 2026. Reddit was notified of the malicious activity associated with the official HBO Max account and immediately suspended the ads. SecurityWeek has emailed Warner Bros., which owns HBO Max, for a statement on the hack and will update this article if the company responds. Related: Personal, Financial Info Exposed in Revolut Data Breach Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution Related: Telus Warns Customers of Account Breaches Related: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Three JFrog Artifactory Flaws Exploited for Backdoor DeploymentConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like AttacksBlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-DaysGitLab Vulnerability Exploited One Day After DisclosureCheck Point Patches Critical VPN VulnerabilitiesSurfshark Systems Targeted by HackersPaperCut Flaws Exploited in AI-Powered AttacksCritical NetScaler Vulnerability Exploited in Attacks Latest News Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety ConstraintsRoot RCE Zero-Day in Cisco Secure Email Gateway Under Active ExploitationBeijing Hits Back at Anthropic CEO’s Call to Curb China’s AI DevelopmentNew Warnings About the Risks of AI to Humanity Revive a Long-Running DebatePersonal, Financial Info Exposed in Revolut Data BreachThe Race to Control AI and Protect What Makes Us HumanChinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code ExecutionCISOs Race to Control AI Agents Without Destroying Their Value Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveZero Networks has named Yossi Dagan as Chief Financial Officer.Manifold has appointed Joe Sullivan to its Board of Directors.Patrick McKinney has joined Turing as Chief Information Security Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- domain — hbomaxx[.]us
- malware — MacSync
- malware — AMOS Helper
- malware — Amatera Stealer
- malware — AnimateClipper
- malware — ZigClipper