Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack

https://www.securityweek.com/wp-content/uploads/2026/02/Reddit.jpeg

Hackers compromised the official HBO Max account on Reddit and used it in a malvertising campaign leading to a ClickFix landing page.

During a 48-hour window, the attackers pushed 108 malicious advertisements across five lure groups as part of the campaign, tracked as PasteSwitch.

Using the verified u/hbomax account, the threat actors targeted both macOS and Windows users and aggressively promoted a native macOS application for HBO Max, which does not exist.

Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also contained a download button.

“The download button opened a ClickFix prompt that told the visitor to copy a command, open Terminal, paste the command, and run it. This transferred execution from the browser to a trusted system utility under the victim’s control,” ADAMnetworks explains.

On macOS, the attack relied on curl | zsh commands to deliver malware such as MacSync...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more