Adam NetworksHBO MaxBleepingComputerMicrosoftMicrosoft CorporationADAMnetworksHudson RockRedditApple Inc.

Hackers hijacked HBO Max's official Reddit account to push malicious ClickFix ads; 108 ads ran over 48 hours, tricking users into installing info-stealing malware on Windows and macOS.

Hackers compromised HBO Max's official Reddit account, launching 108 malicious ads over 48 hours that tricked users into installing info-stealing malware on Windows and macOS. The ClickFix attacks, which exploit users' trust, have become a significant cybersecurity threat, prompting concerns among security researchers.

TechCrunch TechCrunch+2 sources15 September 2026 · 05:08 UTC
CuriousCats Full Story

Hackers hijacked HBO Max's official Reddit account to run a 48-hour campaign of malicious ads, totaling 108 ads that led users to install info-stealing malware on both Windows and macOS systems. The ClickFix attacks exploit users' trust by masquerading as legitimate tech fixes.467

The compromised account was used to post ads that redirected users to a convincing fake HBO Max website, which claimed to offer downloads but instead provided instructions to execute harmful commands in the terminal. Security researchers from Hudson Rock and ADAMnetworks noted that the ClickFix technique tricks users into copying and pasting malicious commands, effectively bypassing traditional security measures.59

According to reports, the campaign is part of a larger operation dubbed PasteSwitch, which targets a wide audience beyond HBO Max users, including developers and those searching for AI software. The ads led to various fake domains, including hbomaxx[.]us and hbomaxx[.]app, promoting fraudulent applications and tools.

The malware deployed in this attack is capable of stealing sensitive information such as passwords, crypto wallet data, and browser credentials. This incident highlights the growing sophistication of cyber threats and the need for enhanced security measures to protect users from such attacks.

Key Insight
“The campaign, dubbed PasteSwitch, also distributed fake Ledger, Trezor Suite, and Exodus crypto wallets to steal recovery phrases. Reddit said it 'paused the affected ads' and locked the account, but it remains unclear how the attackers gained access.”
CuriousCats studied:
1
TechCrunchTechCrunch
“These so-called “ClickFix” attacks have quickly become one of the rising cybersecurity threats of 2026, and they’re getting both sneakier and compromising people’s devices with greater frequency.”
TechCrunch →
2
bleepingcomputer.com
“Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.”
bleepingcomputer.com →
3
PCMag UKPCMag UK
“A hacker hijacked an -focused account on Reddit to trick users into installing that can infect Windows PCs and Macs.”
PCMag UK →
Ask CuriousCats
What happened to HBO Max's Reddit account?
Who was behind the PasteSwitch campaign?
How did the malware affect users' devices?
Are there similar incidents involving other platforms?
Which methods do hackers commonly use for attacks?
Get your CIA-level briefing,
in real time.
CuriousCats monitors the internet every minute for you and brings you the most personalized brief of videos, social media posts, news and more.
Download the App
Liked the depth here?
Get the full internet briefed for you any time of the day.
Get CuriousCats