HBO Max's Verified Reddit Account Hijacked To Spread ClickFix Malware

Cybercriminals compromised the official, verified HBO Max Reddit account and used it to distribute malicious advertisements across the platform. Security researchers say the attackers deployed 108 malicious ads over roughly 48 hours, targeting both Windows and macOS users. The campaign relied on the ClickFix social engineering technique, which tricks victims into pasting attacker-controlled commands into their own systems. Researchers have since connected the incident to a much larger, ongoing operation they call PasteSwitch.

HBO Max's Verified Reddit Account Hijacked To Spread ClickFix Malware

A Reddit user named Alex Cutts first spotted an advertisement from the verified u/hbomax account promoting what appeared to be a native HBO Max application for macOS. The account had a long history of posting in official HBO Max subreddits, which made the advertisement appear trustworthy to unsuspecting viewers. Clicking the ad redirected visitors to hbomaxx[.]us, a convincing fake website that mimicked HBO Max's branding.

The fraudulent page did not actually deliver a downloadable application when visitors clicked the join or download button. Instead, it displayed ClickFix-style instructions telling users to open Terminal or Windows Run and paste a supplied command. This method transfers the actual execution step from the browser to a trusted operating system utility that the victim runs personally.

The Reddit user who discovered the ad described the experience firsthand, noting the campaign's deceptive nature. "The advert takes you to hbomaxx[.]us, which looks somewhat legitimate, and has a join button / download," the user wrote. They added that clicking the button triggered "the classic infostealer/clickfix paste this command to download" pattern common to these attacks.

Security researchers at Hudson Rock and ADAMnetworks jointly investigated the incident after it surfaced publicly on Reddit. Their combined research determined that the compromised account had posted far more than just HBO Max-branded advertisements. Analysis of archived account activity confirmed 108 total ads spread across five distinct lure campaigns during the 48-hour window.

The malicious advertisements did not exclusively impersonate HBO Max, expanding the attack's reach well beyond streaming service subscribers. Researchers identified the following breakdown of ad destinations and their associated themes:

  • 40 ads directed users to hbomaxx[.]app, continuing the HBO Max impersonation theme
  • 36 ads promoted codex-craft[.]com, a fake artificial intelligence and developer tool site
  • 15 ads pointed to apple.clean-disk-guide[.]com, disguised as a macOS disk utility
  • 11 ads led to code-desktop[.]com, targeting developers seeking desktop software
  • 6 ads promoted hbomax-macos[.]com, another HBO Max-themed lure

This diversified approach allowed the attackers to target developers and general software users, not solely HBO Max subscribers. By spreading the campaign across unrelated brands, the operators maximized the number of potential victims who might trust at least one of the advertised products.

Inside the ClickFix Attack Chain

Once victims pasted the malicious command into Terminal, the script executed a Base64 encoded payload designed to obscure its true function. Decoded, the command connected to ember-bridge[.]com, a domain that Hudson Rock had already flagged as active PasteSwitch infrastructure. The script used encryption and compression techniques, including AES-128-CTR, before ultimately launching further malicious code.

Researchers traced the chain to a native macOS payload written to a temporary directory and executed with elevated file permissions. One malware family observed in the campaign, called MacSync, steals browser credentials, Firefox profiles, Telegram data, Apple Notes, and stored macOS passwords. Another payload, referred to as the AMOS helper, establishes long-term persistence and can receive additional tasks from attacker-controlled servers.

The campaign also distributed counterfeit versions of popular cryptocurrency wallet applications, including Ledger, Trezor Suite, and Exodus. These fake apps were engineered specifically to steal wallet recovery phrases, giving attackers direct access to victims' cryptocurrency holdings. On Windows systems, the attackers used a different chain involving mshta and PowerShell commands to disable security protections.

According to ADAMnetworks, one Windows infection chain used a scheduled task to launch 32-bit PowerShell and disable Microsoft's Antimalware Scan Interface entirely. Later stages loaded a strain called Amatera Stealer directly into memory, avoiding detection by never writing the final payload to disk. The malware also used deceptive TLS certificates, presenting Facebook's identity while communicating with a separate command-and-control server.

Hudson Rock and ADAMnetworks say the HBO Max campaign represents just one entry point into a much broader operation they have named PasteSwitch. The name reflects the operation's core mechanism, in which victims paste attacker-supplied commands while the backend infrastructure switches between campaigns, platforms, and payloads. Researchers found that the same underlying route, grammar, API keys, and telemetry patterns recurred across unrelated fake-brand campaigns.

Previous PasteSwitch activity has impersonated Claude, OpenAI's Codex, the macOS utility Alfred, Homebrew, and various GitHub-related tools. Investigators also identified cryptocurrency clipboard-hijacking malware in the operation, including strains called AnimateClipper and ZigClipper. These clippers use smart contracts on the BNB Smart Chain to dynamically store and rotate command-and-control domains.

Registration records tied several domains used in the September campaign to a shared hosting provider, suggesting coordinated infrastructure planning. Researchers also found that many malicious domains were registered in tightly timed batches, sometimes mere seconds apart. This pattern indicates an organized, well-resourced operation rather than a loosely coordinated group of independent actors.

After the malicious advertisements were publicly reported, a Reddit administrator confirmed that the platform had paused the ad campaign entirely. The administrator also stated that the incident had been escalated to Reddit's internal Security and Safety teams for further review. It remains unclear exactly how the attackers gained initial access to the verified HBO Max account.

BleepingComputer reached out to HBO and its parent company, Warner Bros. Discovery, for comment on the security incident. Neither company had responded publicly at the time reporting on the campaign was published. It also remains unknown whether other HBO or Warner Bros. Discovery accounts and internal systems were affected by the same breach.

Share:

facebook
X (Twitter)
linkedin
copy link
Karolis Liucveikis

Karolis Liucveikis

Experienced software engineer, passionate about behavioral analysis of malicious apps

Author and general operator of PCrisk's News and Removal Guides section. Co-researcher working alongside Tomas to discover the latest threats and global trends in the cyber security world. Karolis has experience of over 8 years working in this branch. He attended Kaunas University of Technology and graduated with a degree in Software Development in 2017. Extremely passionate about technical aspects and behavior of various malicious applications.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate