ZeroHour
Story · 7 sources · 7 articlesfirst updated ()

HBO Max's verified Reddit account hijacked to run 108 ClickFix malware ads

highMalwareexploited in the wildimportance 68
What's new: The previous summary covered the core campaign details across six reports. A seventh report (Malwarebytes, 2026-09-15) confirms the findings and adds attribution detail: the PasteSwitch name was coined by ADAMnetworks, and the infrastructure tailors its payload per victim device. No new IOCs, victim counts, or conflicting figures were introduced; all seven reports remain consistent on the…
Merged summary · glm-5.3 · rewritten as coverage arrives

Attackers compromised HBO Max's verified u/hbomax Reddit account to run 108 ClickFix malvertising ads over 48 hours, delivering AMOS, MacSync, and Amatera infostealers plus crypto clipboard hijackers to macOS and Windows users before Reddit paused and secured…

Threat actors hijacked HBO Max's verified Reddit account (u/hbomax) to run 108 malicious ClickFix ads over roughly 48 hours in a campaign tracked as PasteSwitch — a name Malwarebytes credits to ADAMnetworks — and analyzed by Hudson Rock and ADAMnetworks. The ads pushed fake landing pages on lure domains including hbomaxx[.]us, codex-craft[.]com, and code-desktop[.]com (one report counts five lure domains in total), promoting fake HBO Max sites, AI tools, and macOS utilities. The ad mix included 46 HBO Max ads, 36 fake OpenAI Codex ads, 15 fake macOS disk utilities, and 11 developer-tool ads. ClickFix social engineering tricked victims into pasting Base64-obfuscated shell or PowerShell commands into Terminal or Run themselves, with payloads tailored per device. On macOS, victims were served curl | zsh chains deploying MacSync and Atomic macOS Stealer (AMOS) — which harvest browser credentials, Telegram data, Apple Notes, and macOS passwords — along with AMOS Helper persistence; fake Ledger, Trezor Suite, and Exodus wallet apps harvested 12/24-word BIP39 recovery phrases for direct crypto theft. On Windows, an InstallFix chain used an MP3/HTA polyglot with mshta, 32-bit PowerShell, scheduled-task persistence, and AMSI disabling to load Amatera Stealer in memory, with C2 traffic to 77.91.65.13:443 hidden behind a facebook.com TLS SNI. The AnimateClipper and ZigClipper crypto clipboard hijackers swapped copied wallet addresses and used Binance Smart Chain contracts as resilient, rotating C2 dead drops, with 36 mainnet changes observed between March and July 2026; SecurityWeek reports the blockchain-hosted C&C infrastructure has been active since early 2026. Per The Register, Reddit paused the ads three days after a user reported them on September 6; the account has been secured, an investigation is open, and the initial access path remains unclear.

  • Hijacked verified u/hbomax Reddit account ran 108 malicious ClickFix ads in roughly 48 hours
  • Campaign tracked as PasteSwitch, analyzed by Hudson Rock and ADAMnetworks (name coined by ADAMnetworks per Malwarebytes)
  • Lure domains include hbomaxx[.]us, codex-craft[.]com, and code-desktop[.]com; one report counts five lure domains total
  • Ad breakdown: 46 HBO Max ads, 36 fake OpenAI Codex ads, 15 fake macOS disk utilities, 11 developer-tool ads
  • ClickFix lures trick victims into pasting Base64-obfuscated shell or PowerShell commands into Terminal or Run
  • macOS payloads: MacSync and AMOS stealers plus AMOS Helper persistence, harvesting browser credentials, Telegram data, Apple Notes, and macOS passwords
  • Fake Ledger, Trezor Suite, and Exodus wallet apps harvest 12/24-word BIP39 recovery phrases
  • Windows InstallFix chain uses MP3/HTA polyglot, mshta, 32-bit PowerShell, scheduled-task persistence, and AMSI disabling to load Amatera Stealer in memory

Coverage timeline

  1. · 1d ago
    BleepingComputer· 62
    Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

    Hackers hijacked HBO Max's verified Reddit account to run 108 ClickFix ads delivering infostealers and crypto clippers to Windows and macOS users.

  2. · 22h ago
    The Register · Security· 58
    HBO Max Reddit account compromised to serve ClickFix attacks

    Attackers hijacked HBO Max's verified Reddit account to run 108 ClickFix malvertising ads delivering infostealers, loaders, and crypto clippers to Windows and macOS users.

  3. · 16h ago
    GBHackers· 68
    HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware

    Hijacked HBO Max verified Reddit account ran 108 ClickFix malvertising ads delivering AMOS and Amatera stealers plus crypto clippers to macOS and Windows users.

  4. · 14h ago
    Cyber Security News· 63
    Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads

    Hijacked verified HBO Max Reddit account ran 108 ClickFix malvertising ads delivering AMOS infostealers, Windows loaders, and crypto clipboard hijackers.

  5. · 12h ago
    SecurityWeek· 58
    Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack

    Attackers hijacked HBO Max's verified Reddit account to push 108 malicious ads delivering AMOS and Amatera infostealers via ClickFix prompts.

  6. · 11h ago
    Help Net Security· 62
    Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz

    Attackers hijacked HBO Max's verified Reddit account to push 108 ClickFix infostealer ads delivering AMOS, MacSync, and crypto clippers.

  7. · 9h ago
    Malwarebytes Labs· 62
    HBO Max’s verified Reddit account hijacked to spread malware

    Cybercriminals hijacked HBO Max's verified Reddit account to run 108 ClickFix ads pushing AMOS and Amatera infostealers via fake HBO app sites.