- Hackers compromised the official HBO Max Reddit account (u/hbomax) and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.
- The account was used to post 108 malicious advertisements over about 48 hours, tricking users into installing malware.
- Users who clicked the ads were redirected to fake sites like hbomaxx[.]us, which displayed ClickFix instructions to paste commands into Terminal or Command Prompt.
- The commands installed info-stealing malware such as MacSync, AMOS helper, and Amatera Stealer that stole passwords, cookies, and crypto wallets.
- Security researchers Hudson Rock and ADAMnetworks linked the campaign to a larger operation called PasteSwitch, which targets both Windows and macOS systems.
- Reddit locked the compromised account and removed the ads after being alerted to the situation.
- ClickFix attacks have quickly become one of the rising cybersecurity threats, evolving into a massive international effort to hack into people’s computers.
- The attacks involve fake websites that display messages resembling CAPTCHA or anti-bot checkboxes, tricking users into executing commands.
- Hudson Rock noted that the PasteSwitch operation uses attacker-supplied commands that victims paste into their systems, allowing for various types of malware distribution.
- The campaign has also distributed fake cryptocurrency wallet applications designed to steal victims' wallet recovery phrases.
Hackers hijacked HBO Max's official Reddit account to run a 48-hour campaign of malicious ads, totaling 108 ads that led users to install info-stealing malware on both Windows and macOS systems. The ClickFix attacks exploit users' trust by masquerading as legitimate tech fixes.467

The compromised account was used to post ads that redirected users to a convincing fake HBO Max website, which claimed to offer downloads but instead provided instructions to execute harmful commands in the terminal. Security researchers from Hudson Rock and ADAMnetworks noted that the ClickFix technique tricks users into copying and pasting malicious commands, effectively bypassing traditional security measures.59
According to reports, the campaign is part of a larger operation dubbed PasteSwitch, which targets a wide audience beyond HBO Max users, including developers and those searching for AI software. The ads led to various fake domains, including hbomaxx[.]us and hbomaxx[.]app, promoting fraudulent applications and tools.

The malware deployed in this attack is capable of stealing sensitive information such as passwords, crypto wallet data, and browser credentials. This incident highlights the growing sophistication of cyber threats and the need for enhanced security measures to protect users from such attacks.
“The campaign, dubbed PasteSwitch, also distributed fake Ledger, Trezor Suite, and Exodus crypto wallets to steal recovery phrases. Reddit said it 'paused the affected ads' and locked the account, but it remains unclear how the attackers gained access.”








