Hackers hijacked HBO Max’s verified Reddit account and used it to promote malicious advertisements designed to trick Windows and macOS users into installing information-stealing malware.
Security researchers from Hudson Rock and ADAMnetworks said the compromised u/hbomax account was used to publish 108 malicious advertisements over roughly 48 hours. The campaign relied on a technique known as ClickFix, which tricks users into copying and pasting commands into Windows Run, PowerShell, or macOS Terminal while making the process appear to be a legitimate fix, CAPTCHA verification, or software installation.
ClickFix attacks have become increasingly popular because they convince victims to execute the malicious commands themselves using legitimate system tools. This can make the activity harder for some security protections to identify compared with a traditional malware download. The ads were not limited to HBO Max impersonation either, with some promoting fake AI tools, developer software, and macOS utilities.
The campaign came to light after a Reddit user noticed an advertisement posted by the verified HBO Max account promoting what appeared to be a native HBO Max application for macOS. The advertisement redirected users to a convincing fake HBO Max website that offered a download button. Instead of providing a legitimate application, the site instructed visitors to open Terminal and paste a command.
Researchers found that one of the malicious macOS commands used Base64 encoding to hide what it was doing. The attack infrastructure included domains previously associated with the PasteSwitch operation, a broader campaign targeting both Windows and macOS users with information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications.
One malware family involved in the campaign was MacSync, which can steal browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords. Another attack chain used AMOS helper malware to establish persistence and communicate with attacker-controlled servers for additional commands. The campaign also distributed fake Ledger, Trezor Suite, and Exodus wallet applications designed to steal cryptocurrency recovery phrases.
Windows users were targeted with similar ClickFix techniques involving mshta and PowerShell. Researchers observed an attack chain that used an MP3/HTA polyglot to create a scheduled task, launch PowerShell, disable Microsoft’s Antimalware Scan Interface, and generate infrastructure based on information from the victim’s computer. Later stages used obfuscated PowerShell and shellcode to load the Amatera Stealer directly into memory.
The compromised account was used for a much larger advertising campaign rather than targeting only HBO Max users. Researchers identified dozens of advertisements leading to fake HBO Max websites, as well as campaigns promoting fake AI, developer, and system utility websites. This expanded the potential audience to developers and people looking for AI software or macOS utilities.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
After the malicious advertisements were reported, a Reddit administrator paused the ads and reported the incident to Reddit’s security and safety teams. However, it remains unclear how the attackers gained access to the HBO Max Reddit account or whether any other HBO or Warner Bros. Discovery accounts or systems were affected.



