Cybersecurity researchers say hackers took over HBO Max’s official, verified Reddit account and used it to push 108 malicious advertisements over roughly 48 hours, tricking users into installing malware by exploiting the trust that comes with a verified corporate account.
According to researchers at Hudson Rock, the compromised account, u/hbomax, ran ads for a supposed HBO Max app for macOS. HBO Max does not offer a native Mac app; its support page directs Mac users to stream through a web browser instead. Users who clicked the ad were sent to a convincing landing page, but clicking the download button did not start a file download. Instead, the site instructed visitors to copy and paste a command into their computer’s Terminal application.
Security professionals say that instruction is a major red flag. No legitimate consumer software requires users to manually paste commands into Terminal, PowerShell or the Windows Run dialog to install it or prove they are human.
A technique called ClickFix
The method used in the campaign is known as ClickFix, in which a malicious webpage manipulates a visitor into carrying out the attack themselves rather than relying purely on a hidden download. The page may claim there’s a CAPTCHA error, a browser glitch, or an installation step that needs fixing, then places a command on the user’s clipboard and tells them where to paste it.
Hudson Rock says the HBO Max scheme relied on getting victims to run attacker-supplied code through Terminal, a method that can sidestep some protections built to catch malicious downloads. Researchers say a separate Windows-focused branch of the operation used PowerShell and other tools, in some cases loading malware directly into a computer’s memory without ever writing a file to disk.
Over the two-day campaign, the ads cycled through 108 different lures — including the fake HBO Max download along with pitches for AI tools, developer software and Mac utilities — switching frequently as individual websites were taken down.
A wider operation called PasteSwitch
Hudson Rock and researchers at ADAMnetworks linked the HBO Max campaign to a larger scheme they call PasteSwitch, named for the consistent element across all its variations: a victim pastes an attacker-supplied command, while the software delivered afterward changes depending on the visitor’s device and the specific campaign.
On Macs, researchers identified malware called MacSync capable of stealing browser credentials, Gecko browser profiles, Telegram data, Apple Notes and macOS passwords, along with a separate tool called AMOS that could maintain ongoing access to an infected machine. The operation also used fake versions of cryptocurrency wallet apps — including Ledger, Trezor Suite and Exodus — designed to steal 12- and 24-word wallet recovery phrases.
On Windows, researchers found a chain using mshta and PowerShell that disguised a malicious file as an MP3/HTA before creating a scheduled task to launch further stages, ultimately injecting malware known as Amatera Stealer directly into memory. Researchers also found the malware disguising its network traffic to look like ordinary Facebook activity.
PasteSwitch was also tied to clipboard-hijacking malware called AnimateClipper and ZigClipper, which monitor a victim’s clipboard and swap in a different cryptocurrency wallet address when the victim copies or pastes one — meaning a user could copy a correct address and still send funds to an attacker. Researchers said the operation used Binance Smart Chain contracts to retrieve changing command-and-control domains, observing 36 such changes from the same attacker-controlled address between March and July 2026.
Reddit and HBO Max respond
Reddit confirmed that an HBO Max account authorized to run advertisements on its platform had been compromised. In a statement, the company said:
You must be logged in to post a comment Login