Full Breakdown
HBO Max Reddit Account Hijacked to Distribute ClickFix Malware
By Drooid · · How we work
Account Takeover and Initial Discovery
On September 6, a Reddit user identified a series of malicious advertisements posted from the verified HBO Max Reddit account (u/hbomax). The ads promoted a non-existent macOS HBO Max client and directed users to a landing site (hbomaxx.us) that instructed macOS users to paste a Terminal command, a classic ClickFix infostealer technique. The researcher sandbox-tested the flow and concluded the Reddit account had been compromised.
PasteSwitch Malvertising Campaign
Security firms Hudson Rock and ADAMnetworks linked the hijacked posts to a broader 48-hour “PasteSwitch” operation that deployed 108 distinct ads across multiple lures. - 46 used the HBO Max brand, pointing to hbomaxx.app or hbomax-macos.com. - 36 masqueraded as OpenAI Codex promotions (codex-craft.com). - 15 pretended to be a macOS disk-utility tool (apple.clean-disk-guide.com). - 11 employed other developer-tool themes (code-desktop.com).
The payloads varied by target OS: Windows or macOS infostealers, malware loaders, cryptocurrency clippers (AnimateClipper or ZigClipper), and counterfeit crypto-wallet apps. The clippers leveraged Binance Smart Chain contracts to fetch command-and-control (C2) domains dynamically, giving the attackers “dynamic resilience” to rotate burned domains.
Platform and Corporate Responses
Reddit’s safety and security teams paused the malicious ads within three days and opened an investigation. A Reddit administrator confirmed the investigation but provided no further details. Warner Bros. Discovery, HBO Max’s parent company, did not respond to inquiries about the takeover or its origins.
Verbatim Quotes
- “Between March and July 2026, researchers observed 36 mainnet changes executed by the same attacker controller address,” — Hudson Rock
Broader Implications
The continued reliance on ClickFix tactics suggests that social-engineering attacks exploiting reputable brand accounts will remain a persistent threat to both Windows and macOS users.
