Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Top 10 Cloud Infrastructure Entitlement Management (CIEM) Tools for 2026
September 15, 2026
Top Container Security Tools for 2024
September 15, 2026
Top Kubernetes Security Tools for 2026
September 15, 2026
Home/Threats/Threat Actors Compromise HBO Max Reddit Account to Promote Malware
Threats

Threat Actors Compromise HBO Max Reddit Account to Promote Malware

Key Takeaways A verified HBO Max Reddit account was compromised to distribute malware through fraudulent ads. The campaign, dubbed “PasteSwitch” and “ClickFix,” lured users...

Marcus Rodriguez
Marcus Rodriguez
September 15, 2026 4 Min Read
2 0

Key Takeaways

  • A verified HBO Max Reddit account was compromised to distribute malware through fraudulent ads.
  • The campaign, dubbed “PasteSwitch” and “ClickFix,” lured users with fake software, including a non-existent macOS HBO Max app.
  • Victims were tricked into executing malicious commands via Terminal, leading to the potential installation of credential stealers, cryptocurrency clippers, and other malware.
  • The attack leveraged social engineering and brand impersonation rather than software vulnerabilities, demonstrating the ongoing threat of malvertising.

Hackers Exploit Verified Reddit Account in Sophisticated Malware Campaign

In a concerning development for online security, threat actors successfully hijacked a verified Reddit account belonging to HBO Max, u/hbomax, to disseminate malware. Over a 48-hour period, the compromised account published 108 malicious “ClickFix” advertisements, redirecting unsuspecting users to deceptive web pages promoting fake software.

Table Of Content

  • Key Takeaways
  • Hackers Exploit Verified Reddit Account in Sophisticated Malware Campaign
  • PasteSwitch: A Multi-Platform Malvertising Operation
  • The HBO Max Incident: A Case Study in Deception
  • PasteSwitch’s Expanding Reach Across Platforms
  • What You Should Do

This attack did not exploit a software vulnerability, but rather relied on a sophisticated social engineering approach. The attackers crafted a convincing landing page that mimicked official HBO Max branding, offering a purported native HBO Max application for macOS. Crucially, instead of providing a direct download, the page instructed visitors to copy and paste a command directly into their system’s Terminal, thereby tricking users into manually executing attacker-controlled code.

PasteSwitch: A Multi-Platform Malvertising Operation

Researchers at HudsonRock, collaborating with independent cybersecurity expert Kirk from ADAMnetworks, have identified this activity as part of a broader, cross-platform malicious operation they’ve named PasteSwitch. HudsonRock said in a report that PasteSwitch extends beyond fake streaming apps, encompassing lures for AI tools, developer utilities, and disk-cleaning software. The potential ramifications of this operation are extensive.

The report, also detailed in a detailed analysis, indicates that PasteSwitch is capable of deploying a range of malicious payloads, including credential stealers, Windows loaders, and cryptocurrency-address clippers. This poses significant risks to browser data, saved passwords, and digital assets.

The operation’s adaptability is a key concern. It employs a reusable framework that allows attackers to easily swap out brands, lures, and payloads while maintaining consistent underlying delivery mechanisms. Reddit has since paused the malicious ads and launched an investigation. This incident serves as a stark reminder that a verified account does not inherently guarantee the safety of associated downloads or promotions.

The HBO Max Incident: A Case Study in Deception

The suspicious advertising came to light after a Reddit user encountered what appeared to be an official ad from u/hbomax. The ad promoted a macOS application for HBO Max, despite no such standalone app officially existing. The linked landing page meticulously replicated HBO Max branding, creating a compelling illusion before presenting its malicious trap.

The “ClickFix” method bypasses traditional software installation by prompting users for a manual action. Upon clicking “Download,” an overlay appeared, instructing the user to copy and paste a command into their Terminal. This technique, demonstrated in other recent ClickFix malware attacks, effectively manipulates users into executing attacker-supplied code on their systems.

The threat actors exhibited agility in their campaign, rapidly cycling through domains as they were detected and blocked. The ads included 40 streaming-themed placements using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-desktop[.]com, and six for hbomax-macos[.]com. The compromised HBO Max account provided a trusted advertising platform for two days, leveraging brand reputation to lower user vigilance.

PasteSwitch’s Expanding Reach Across Platforms

The researchers uncovered a dynamic delivery system that adapts to the visitor’s operating system and the specific campaign. For macOS users, the pasted command could fetch MacSync, AMOS-related helpers, or fake cryptocurrency wallet applications. These payloads are designed to harvest credentials, Telegram data, Apple Notes, and macOS passwords, with fake wallets specifically targeting recovery phrases.

Windows users were directed through a separate “InstallFix” route, utilizing mshta and PowerShell. This involved a disguised MP3/HTA file that could establish a scheduled task, launch 32-bit PowerShell, and disable the Antimalware Scan Interface before executing further malicious code. The “Amatera” payload could then load directly into memory, evading file-based security checks. Furthermore, the report documented deceptive TLS traffic, where connections to attacker-controlled IPs presented “facebook.com” as the visible server name, potentially misleading basic network logs.

An additional threat vector of the operation is its “clipper” branch. “AnimateClipper” and “ZigClipper” monitor the victim’s clipboard, automatically replacing copied cryptocurrency addresses with an attacker’s address. These clipper modules can retrieve current command-and-control domains from Binance Smart Chain contracts, enabling the actors to frequently rotate their infrastructure and maintain persistence.

What You Should Do

  • Exercise Extreme Caution with Copy-Paste Commands: Never copy and paste commands from advertisements, pop-ups, or websites into your Terminal or command prompt, especially if prompted by an unexpected download. Always validate software through official vendor channels.
  • Verify Software Sources: Download applications only from official app stores (e.g., Apple App Store, Microsoft Store) or directly from the legitimate vendor’s website. Be wary of third-party download sites or ads promoting “native” versions of software that may not exist.
  • Monitor for Unusual Activity: Defenders should block all listed Indicators of Compromise (IoCs). Investigate any alerts related to unexpected Terminal, Run-dialog, mshta, or PowerShell activity.
  • Review and Reset Credentials: If you suspect exposure, immediately reset passwords for affected accounts and enable multi-factor authentication (MFA) wherever possible. Monitor for unusual browser data collection.
  • Enhance Network Monitoring: Network teams should correlate direct IP connections with suspicious SNI (Server Name Indication), DNS, and certificate behavior. Pay close attention to blockchain-based command-and-control channels in investigations.
  • Educate Users: Regularly remind staff and users about the dangers of malvertising, social engineering tactics, and the importance of verifying software sources.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwareSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical Cisco Secure Email Gateway Flaw Under Active Exploit

Next Post

10 Best Serverless Security Solutions for 2026

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Cisco Secure Email Gateway Flaw Under Active Exploit
September 15, 2026
Top 10 CASB Solutions for Cloud Security in 2026
September 15, 2026
Revolut Data Breach: Attackers Impersonate Government for Customer Data
September 15, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us