Hackers seized the official HBO Max Reddit account and pushed 108 malicious ads in 48 hours, luring macOS and Windows users to a ClickFix page that installs malware. The attack deploys MacSync, AMOS Helper, fake wallet apps on macOS and Amatera Stealer on Windows, stealing credentials and maintaining persistence.

  • HBO Max's Reddit account was hijacked to run 108 malicious ads.
  • Users were redirected to a ClickFix page that pushed malware downloads.
  • The malware steals data and establishes persistent access on macOS and Windows.

Hackers hijacked HBO Max’s official Reddit account and, over a 48‑hour window, pushed 108 malicious advertisements across five lure groups, tracked as PasteSwitch. The campaign targeted both macOS and Windows users, aggressively promoting a nonexistent native macOS HBO Max app.

Clicking the malicious ads directed users to hbomaxx.us, a site mimicking the official HBO Max portal with a download button. The button triggered a ClickFix prompt instructing users to copy a command, open Terminal, paste the command, and run it, effectively transferring execution from the browser to a trusted system utility.

On macOS, the attack leveraged curl | zsh commands to deliver malware such as MacSync, AMOS Helper, fake wallet applications, and other malicious code that steals credentials, messages, browser data, and cryptocurrency wallet information, while maintaining persistent access.

On Windows, the attackers used MSHTA and PowerShell to deliver Amatera Stealer, achieving persistence and bypassing network telemetry by spoofing Facebook connections to conceal its command‑and‑control (C&C) traffic.

The PasteSwitch campaign also employed AnimateClipper and ZigClipper as persistent clipboard replacement tools, swapping cryptocurrency addresses during user transactions. These clipboard stealers use a C&C hosted on the blockchain, a setup that has been active for over a year.

Reddit was notified of the malicious activity linked to the official HBO Max account and immediately suspended the ads. SecurityWeek has emailed Warner Bros. for a statement and will update the article if the company responds.

Why This Matters

BozokMedia analysis shows that compromising official social media accounts can enable sophisticated malware distribution, highlighting the need for robust account security and vigilant monitoring.

“Security teams must prioritize two‑factor authentication and continuous monitoring of official accounts to prevent similar breaches.”
Did You Know?: ClickFix has been a popular technique among cybercriminals since 2017, allowing attackers to gain system control with minimal user suspicion.

Frequently Asked Questions

Q1: Has my data been compromised? If you clicked the malicious ads, there is a risk that your credentials and personal data were exposed.

Q2: How can I protect my system? Keep your OS and antivirus up to date, avoid downloading from unknown sources, and enable two‑factor authentication.