HBO Max Reddit account compromised to serve ClickFix attacks
Unknown attackers compromised HBO Max's official Reddit account and used it to push more than 100 malicious adverts distributing information-stealing malware to both Windows and macOS users. The incident, uncovered by a Reddit user on 6 September, formed part of a wider "48-hour malvertising blitz" that abused trusted brand accounts to trick victims into running malicious commands, highlighting how attackers increasingly exploit verified social media accounts to bypass user suspicion.
The malicious HBO Max ads led to a fake landing page offering a non-existent macOS app, which used a "ClickFix" technique to trick users into pasting a command into Terminal, ultimately deploying infostealer malware. Researchers at Hudson Rock and ADAMnetworks named the wider campaign PasteSwitch, noting it delivered 108 distinct ads exploiting lures including HBO Max (46 ads), fake OpenAI Codex tools (36 ads), a bogus macOS disk utility (15 ads) and other developer tools (11 ads); payloads included infostealers, cryptocurrency clippers using blockchain-based command-and-control infrastructure, and fake crypto wallet apps. Reddit paused the ads three days after discovery and said its security teams were investigating, while Warner Bros. Discovery had not responded to queries about the takeover.
- Hackers hijacked HBO Max's Reddit account to spread malware via fake ads.
- Attack used "ClickFix" trick, part of a 108-ad malvertising campaign.
- Reddit paused the ads; Warner Bros. Discovery hasn't explained the breach.