ZeroHour
SecurityWeekpublished ()ingested Ionut Arghire
Part of a story covered by 7 sources: “HBO Max's verified Reddit account hijacked to run 108 ClickFix malware ads” — merged summary and timeline →

Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack

highMalware exploited in the wildimportance 58
AI summary · glm-5.3

Attackers hijacked HBO Max's verified Reddit account to push 108 malicious ads delivering AMOS and Amatera infostealers via ClickFix prompts.

Threat actors compromised the official u/hbomax Reddit account and ran 108 malicious ads over 48 hours in a campaign tracked as PasteSwitch, directing users to a fake hbomaxx[.]us site. ClickFix prompts tricked macOS users into running curl | zsh payloads (MacSync, AMOS Helper, fake wallets) and Windows users into executing MSHTA/PowerShell delivering Amatera Stealer. AnimateClipper and ZigClipper clipboard hijackers swapped cryptocurrency addresses using a blockchain-hosted C&C active since early 2026. Reddit suspended the ads after notification.

  • 108 malicious ads in 48 hours via verified u/hbomax account
  • ClickFix prompts run curl | zsh on macOS, MSHTA/PowerShell on Windows
  • Delivers MacSync, AMOS Helper, Amatera Stealer, fake wallets
  • Clipboard hijackers swap crypto addresses with blockchain-hosted C&C
  • Reddit suspended the ads; infrastructure used since early 2026

Indicators of compromiseAll →

TypeIndicatorContext
domainhbomaxx.usich does not exist. Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also con
Full article364 words · extracted from securityweek.com · click to collapse

Hackers compromised the official HBO Max account on Reddit and used it in a malvertising campaign leading to a ClickFix landing page.

During a 48-hour window, the attackers pushed 108 malicious advertisements across five lure groups as part of the campaign, tracked as PasteSwitch.

Using the verified u/hbomax account, the threat actors targeted both macOS and Windows users and aggressively promoted a native macOS application for HBO Max, which does not exist.

Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also contained a download button.

“The download button opened a ClickFix prompt that told the visitor to copy a command, open Terminal, paste the command, and run it. This transferred execution from the browser to a trusted system utility under the victim’s control,” ADAMnetworks explains.

On macOS, the attack relied on curl | zsh commands to deliver malware such as MacSync, AMOS Helper, fake wallet applications, and other malicious code to steal users’ information, including their credentials, messages, browser information, and cryptocurrency wallet information, and gain persistent access to their machines.

Advertisement. Scroll to continue reading.

On Windows, the attack relied on MSHTA and PowerShell to deliver the Amatera Stealer and achieve persistence. Configured for manual credential validation, the malware would bypass network telemetry by spoofing Facebook connections to hide its command-and-control (C&C) communication.

The PasteSwitch campaign also used AnimateClipper and ZigClipper as persistent clipboard replacement tools to swap cryptocurrency addresses when users attempted to make a transaction, HudsonRock notes.

According to the security firms, the clipboard stealers use a C&C hosted on the blockchain. The infrastructure was likely set up over a year ago and has been used in attacks since early 2026.

Reddit was notified of the malicious activity associated with the official HBO Max account and immediately suspended the ads.

SecurityWeek has emailed Warner Bros., which owns HBO Max, for a statement on the hack and will update this article if the company responds.

Related: Personal, Financial Info Exposed in Revolut Data Breach

Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Related: Telus Warns Customers of Account Breaches

Related: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/hacked-hbo-reddit-account-used-for-malware-delivery-via-clickfix-attack/