Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Social Engineering

Hackers Hijack HBO Max Reddit Account to Push ClickFix Malware

2 reports · First detected 2026-09-16 · Last active 2026-09-17

ClickFix attacks bypass conventional download warnings by persuading users to paste attacker-supplied commands into Terminal, PowerShell or Windows Run. Cybercrime intelligence firm Hudson Rock and network security company ADAMnetworks linked the HBO Max incident to PasteSwitch, a broader cross-platform operation. The abuse of a verified corporate account is significant because it turned Reddit’s trust signals and advertising reach into tools for distributing credential stealers and bogus cryptocurrency wallets.

A Reddit user flagged the verified u/hbomax account on Sept. 6 after it advertised a native HBO Max macOS app that does not exist. Researchers disclosed on Sept. 14 that the hijacked account served 108 malicious ads in roughly 48 hours. Windows targets received Amatera Stealer, while macOS users were exposed to MacSync and AMOS Helper; fake Ledger, Trezor Suite and Exodus apps sought wallet recovery phrases. Reddit paused the ads and opened an investigation, while victim totals and financial losses remain unconfirmed.

All Coverage

2 original reports

The Backstory

The history behind this event

This is the first time the radar has seen this story

See the “Social Engineering” timeline →
Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)