HBO Max's verified Reddit account hijacked to run 108 ClickFix malware ads
Attackers compromised HBO Max's verified u/hbomax Reddit account to run 108 ClickFix malvertising ads over 48 hours, delivering AMOS, MacSync, and Amatera infostealers plus crypto clipboard hijackers to macOS and Windows users before Reddit paused and secured…
Threat actors hijacked HBO Max's verified Reddit account (u/hbomax) to run 108 malicious ClickFix ads over roughly 48 hours in a campaign tracked as PasteSwitch — a name Malwarebytes credits to ADAMnetworks — and analyzed by Hudson Rock and ADAMnetworks. The ads pushed fake landing pages on lure domains including hbomaxx[.]us, codex-craft[.]com, and code-desktop[.]com (one report counts five lure domains in total), promoting fake HBO Max sites, AI tools, and macOS utilities. The ad mix included 46 HBO Max ads, 36 fake OpenAI Codex ads, 15 fake macOS disk utilities, and 11 developer-tool ads. ClickFix social engineering tricked victims into pasting Base64-obfuscated shell or PowerShell commands into Terminal or Run themselves, with payloads tailored per device. On macOS, victims were served curl | zsh chains deploying MacSync and Atomic macOS Stealer (AMOS) — which harvest browser credentials, Telegram data, Apple Notes, and macOS passwords — along with AMOS Helper persistence; fake Ledger, Trezor Suite, and Exodus wallet apps harvested 12/24-word BIP39 recovery phrases for direct crypto theft. On Windows, an InstallFix chain used an MP3/HTA polyglot with mshta, 32-bit PowerShell, scheduled-task persistence, and AMSI disabling to load Amatera Stealer in memory, with C2 traffic to 77.91.65.13:443 hidden behind a facebook.com TLS SNI. The AnimateClipper and ZigClipper crypto clipboard hijackers swapped copied wallet addresses and used Binance Smart Chain contracts as resilient, rotating C2 dead drops, with 36 mainnet changes observed between March and July 2026; SecurityWeek reports the blockchain-hosted C&C infrastructure has been active since early 2026. Per The Register, Reddit paused the ads three days after a user reported them on September 6; the account has been secured, an investigation is open, and the initial access path remains unclear.
- Hijacked verified u/hbomax Reddit account ran 108 malicious ClickFix ads in roughly 48 hours
- Campaign tracked as PasteSwitch, analyzed by Hudson Rock and ADAMnetworks (name coined by ADAMnetworks per Malwarebytes)
- Lure domains include hbomaxx[.]us, codex-craft[.]com, and code-desktop[.]com; one report counts five lure domains total
- Ad breakdown: 46 HBO Max ads, 36 fake OpenAI Codex ads, 15 fake macOS disk utilities, 11 developer-tool ads
- ClickFix lures trick victims into pasting Base64-obfuscated shell or PowerShell commands into Terminal or Run
- macOS payloads: MacSync and AMOS stealers plus AMOS Helper persistence, harvesting browser credentials, Telegram data, Apple Notes, and macOS passwords
- Fake Ledger, Trezor Suite, and Exodus wallet apps harvest 12/24-word BIP39 recovery phrases
- Windows InstallFix chain uses MP3/HTA polyglot, mshta, 32-bit PowerShell, scheduled-task persistence, and AMSI disabling to load Amatera Stealer in memory
Coverage timelineoldest first · each row is one article
- · 1d agoHackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer· 62
Hackers hijacked HBO Max's verified Reddit account to run 108 ClickFix ads delivering infostealers and crypto clippers to Windows and macOS users.
- · 22h agoHBO Max Reddit account compromised to serve ClickFix attacks
The Register · Security· 58
Attackers hijacked HBO Max's verified Reddit account to run 108 ClickFix malvertising ads delivering infostealers, loaders, and crypto clippers to Windows and macOS users.
- · 16h agoHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers· 68
Hijacked HBO Max verified Reddit account ran 108 ClickFix malvertising ads delivering AMOS and Amatera stealers plus crypto clippers to macOS and Windows users.
- · 14h agoHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News· 63
Hijacked verified HBO Max Reddit account ran 108 ClickFix malvertising ads delivering AMOS infostealers, Windows loaders, and crypto clipboard hijackers.
- · 12h agoHacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack
SecurityWeek· 58
Attackers hijacked HBO Max's verified Reddit account to push 108 malicious ads delivering AMOS and Amatera infostealers via ClickFix prompts.
- · 11h agoAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security· 62
Attackers hijacked HBO Max's verified Reddit account to push 108 ClickFix infostealer ads delivering AMOS, MacSync, and crypto clippers.
- · 9h agoHBO Max’s verified Reddit account hijacked to spread malware
Malwarebytes Labs· 62
Cybercriminals hijacked HBO Max's verified Reddit account to run 108 ClickFix ads pushing AMOS and Amatera infostealers via fake HBO app sites.