Cybercriminals have compromised HBO Max's verified Reddit account to distribute malicious ads using the 'ClickFix' technique, targeting both Windows and macOS users with information-stealing malware.

  • The verified u/hbomax Reddit account was used to post 108 malicious advertisements.
  • The 'ClickFix' social engineering technique tricks users into running malicious commands manually.
  • The campaign, dubbed 'PasteSwitch', targets Windows and macOS to steal credentials and crypto assets.
  • Malware families like MacSync and Amatera Stealer are being deployed.

In a sophisticated breach of digital trust, hackers have compromised the official HBO Max Reddit account, turning a verified brand presence into a weapon for cyberattacks. Security researchers from Hudson Rock and ADAMnetworks revealed that the hijacked account was used to launch a massive wave of 108 malicious advertisements over a 48-hour period.

The core of this campaign is a deceptive social engineering tactic known as ClickFix. Unlike traditional malware that relies on silent downloads, ClickFix actively manipulates the user. It presents fake error messages or CAPTCHA prompts that instruct users to copy and paste specific commands into Windows Run, PowerShell, or the macOS Terminal. By convincing victims to execute these commands themselves, the attackers effectively bypass many browser-based and OS-level security protections.

Why This Matters

BozokMedia analysis shows that this attack highlights a growing trend where the 'human element' is the primary vulnerability. By leveraging the authority of a verified account, attackers bypass the natural skepticism users have toward unknown links, making the social engineering aspect of ClickFix incredibly potent.

The danger of ClickFix lies in its ability to turn a user's own administrative tools into weapons against their own system.

The researchers have identified this operation as part of a broader campaign called 'PasteSwitch'. This campaign is highly versatile, switching between different payloads, platforms, and theft methods based on the target. While some ads impersonated HBO Max to offer fake macOS apps, others promoted fraudulent AI tools and developer software to cast a wider net across the tech-savvy community.

On the macOS side, the malware MacSync has been identified, which is capable of exfiltrating browser credentials, Telegram data, and even Apple Notes. For Windows users, the attackers utilize Amatera Stealer, often loading it directly into memory to avoid detection by disk-scanning antivirus software. Furthermore, the campaign has been linked to cryptocurrency theft, distributing fake Ledger and Trezor wallet applications to steal recovery phrases.

Did You Know?: The 'PasteSwitch' name refers to the attacker's backend capability to switch between different malware payloads depending on whether the victim is using Windows or macOS.

Frequently Asked Questions

Question 1: How can I tell if an ad is a ClickFix attack?
Answer: If a website asks you to open your Terminal, PowerShell, or Command Prompt to 'fix an error' or 'verify your identity' by pasting a code, it is almost certainly a scam.

Question 2: What should I do if I already ran a command?
Answer: Immediately disconnect your device from the internet, use a clean device to change all your important passwords (especially banking and email), and run a deep system scan with reputable anti-malware software.

Attack VectorClickFix MethodStandard Malware
User InteractionManual command pastingAutomated file execution
Detection DifficultyVery High (Uses OS tools)Moderate (Detected by AV)
Primary GoalCredential & Crypto TheftSystem Control/Ransom