HBO Max Reddit account compromised to serve ClickFix attacks
Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware
cyber-crime
HBO Max Reddit account compromised to serve ClickFix attacks
Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware
Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware.
A Reddit user uncovered the infostealer ads on September 6, noting that the ad showed u/hbomax as the author — this is the verified HBO Max account — and advertised a macOS app for HBO Max. The streaming service does not offer a native client for the Mac.
Anyone who clicked on the malicious ad would then be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button.
Clicking the button produced instructions telling the user to copy and paste a command into Terminal on macOS.
The Reddit security sleuth described that as “the classic infostealer/clickfix paste this command to download,” noting that they tested all of this in a sandboxed environment, and didn’t actually run the executable on their machine. “My guess is that the Reddit account is compromised,” they concluded.
Three days later, Reddit paused the infostealer-dropping ads, and an admin said the social media platform’s safety and security teams were investigating what happened.
HBO Max’s parent company Warner Bros. Discovery didn’t immediately respond to The Register’s inquiries about the account takeover - including who hijacked the streaming service’s Reddit account and how they did it. Maybe someone who didn’t like the House of the Dragon season 3 finale? We will update this story if and when we hear back.
Researchers at Hudson Rock and ADAMnetworks analyzed the ads, and in a couple of reports said the HBO Max account hijacking was part of a “massive 48-hour malvertising blitz” that pushed 108 distinct ads using multiple software lures.
They named the campaign PasteSwitch, and said it serves up targeted malware aimed at victims’ operating system - either macOS or Windows. The payloads include infostealers, malware loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications.
The cryptocurrency clippers - PasteSwitch delivers either AnimateClipper or ZigClipper - also provide blockchain-based command-and-control fallbacks for the attackers. They use Binance Smart Chain (BSC) contracts to dynamically fetch whatever C2 domain the crooks are using at any given time.
“Between March and July 2026, researchers observed 36 mainnet changes executed by the same attacker controller address,” Hudson Rock said. “Because the C2 domain is hosted directly on the blockchain, the infrastructure demonstrates dynamic resilience, allowing the threat actors to easily rotate burned domains.”
In addition to HBO Max, the attackers used developer-tool, disk-cleaner, and AI-themed lures, including fake OpenAI Codex ads, which crims have previously used to push Mac malware.
Of the 108 ads, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com).
“The campaign proves once again why trusted distribution channels are becoming prime targets for infostealer delivery,” Hudson Rock co-founder and CTO Alon Gal said in a LinkedIn post.
It also shows that miscreants continue to make heavy use of ClickFix attacks, so there’s little sign this social engineering method is going away anytime soon.®
Originally published on The Register


