Hacked HBO Reddit Account Used for Malware Delivery via ClickFix Attack
Hackers exploited a compromised HBO Max Reddit account to launch a malvertising campaign using ClickFix, delivering malware to macOS and Windows users. The campaign aimed to install malicious applications, steal user data including credentials and cryptocurrency information, and establish persistent access to victims' machines.
Hackers gained control of the official HBO Max Reddit account and leveraged it to execute a sophisticated malvertising campaign. The campaign utilized ClickFix, a technique that redirects users to a fake HBO Max website (hbomaxx[.]us) containing a download button. Clicking this button triggered a ClickFix prompt, instructing users to copy and paste a command into their terminal, effectively transferring execution from the browser to a trusted system utility.
On macOS, the attack utilized curl and zsh commands to deliver malware, including MacSync, AMOS Helper, and fake wallet applications, designed to steal user information such as credentials, messages, browser data, and cryptocurrency wallet details, and maintain persistent access to compromised machines. On Windows, the attack employed MSHTA and PowerShell to deploy Amatera Stealer, a malware designed to steal user information and establish persistence. The PasteSwitch campaign also deployed AnimateClipper and ZigClipper as persistent clipboard replacement tools, swapping cryptocurrency addresses during transactions.
The infrastructure supporting the PasteSwitch campaign has been operational since early 2026 and is hosted on a blockchain-based C&C. Reddit was notified of the malicious activity and promptly suspended the associated ads. Warner Bros., the owner of HBO Max, has not yet responded to a request for comment.