Cybersecurity

HBO Max’s Verified Reddit Account Hacked to Promote Malware-Linked Ads

Attackers hijacked HBO Max’s verified Reddit account and posted 108 malicious advertisements over approximately 48 hours. The ads used the ClickFix technique to persuade users to execute malicious commands on Windows and macOS. Researchers linked the campaign to the PasteSwitch operation, which distributes data- and cryptocurrency-stealing malware.

2026-09-14
3 min read
7 views
فريق تحرير certi.news
HBO Max’s Verified Reddit Account Hacked to Promote Malware-Linked Ads

HBO Max’s official, verified Reddit account was used to publish 108 malicious advertisements over approximately 48 hours, according to an analysis by Hudson Rock and ADAMnetworks. The ads directed users on Windows and macOS devices to attacks based on the ClickFix technique, which pretends to fix an error, pass a CAPTCHA test, or install legitimate software, then asks the victim to copy and paste a command into Windows Run, PowerShell, or Terminal on macOS.

The technique is dangerous because the user executes the command themselves using trusted system tools, which may help the malware bypass some browser mechanisms or security tools focused on detecting suspicious downloads. The ads did not only impersonate HBO Max; they also included artificial-intelligence tools, developer software, and macOS utilities.

Verified Account Leads to Fake Application

The campaign was first observed after a user noticed an advertisement promoting an alleged HBO Max macOS application. The report said the ad directed visitors to domains resembling the service’s websites, including hbomaxx[.]us, where a download button instead displayed instructions asking users to open Terminal and paste a command to install the program.

One sequence used commands concealed with Base64 encoding, while Hudson Rock said that the domain ember-bridge[.]com had been used in September to deliver malware as part of the PasteSwitch operation. The malware observed included the MacSync family, which can steal browser credentials, Firefox files, Telegram data, Apple Notes content, and macOS passwords. Another sequence was observed using malware called AMOS helper to establish persistence on the device and communicate with servers controlled by the attackers.

Campaign Broader Than HBO Max Impersonation

Researchers linked the incident to the PasteSwitch operation, a campaign that changes its payload, target, and platform depending on the visitor. The operation also distributed fake applications for Ledger, Trezor Suite, and Exodus wallets in an attempt to steal wallet recovery phrases, along with information-stealing malware, payload downloaders, and malware that hijacks clipboard contents associated with cryptocurrencies.

On Windows, some sequences used mshta and PowerShell, creating scheduled tasks, disabling the Microsoft Antimalware Scan Interface, and loading Amatera Stealer directly into memory. The AnimateClipper and ZigClipper malware were also observed stealing cryptocurrency addresses from the clipboard.

Why Does This Matter?

The incident shows that an account’s credibility or verification badge is not enough to prove that an advertisement is safe, especially when official accounts are exploited to reach audiences looking for well-known services or technical tools. The variety of the ads also shows that the threat did not target the HBO Max audience alone; researchers counted 40 ads directing users to hbomaxx[.]app, 36 ads for an artificial-intelligence and development tools website, and 15 ads for a macOS cleaning tool, in addition to other domains.

Reddit moderators removed the ads after they were reported and referred them to the platform’s security and safety teams. It remains unclear how the attackers gained access to the HBO Max account, or whether other accounts or systems belonging to HBO or Warner Bros. Discovery were affected. The two companies did not respond to BleepingComputer’s questions by the time the report was published.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news