Hackers Hijack HBO Max Reddit Account to Push ClickFix Malware
ClickFix attacks bypass conventional download warnings by persuading users to paste attacker-supplied commands into Terminal, PowerShell or Windows Run. Cybercrime intelligence firm Hudson Rock and network security company ADAMnetworks linked the HBO Max incident to PasteSwitch, a broader cross-platform operation. The abuse of a verified corporate account is significant because it turned Reddit’s trust signals and advertising reach into tools for distributing credential stealers and bogus cryptocurrency wallets.
A Reddit user flagged the verified u/hbomax account on Sept. 6 after it advertised a native HBO Max macOS app that does not exist. Researchers disclosed on Sept. 14 that the hijacked account served 108 malicious ads in roughly 48 hours. Windows targets received Amatera Stealer, while macOS users were exposed to MacSync and AMOS Helper; fake Ledger, Trezor Suite and Exodus apps sought wallet recovery phrases. Reddit paused the ads and opened an investigation, while victim totals and financial losses remain unconfirmed.
All Coverage
2 original reportsThe Backstory
The history behind this eventThis is the first time the radar has seen this story
See the “Social Engineering” timeline →Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →