HBO Max Reddit Account Used to Push Malware via ClickFix

Attackers hijacked the verified u/hbomax Reddit account and ran 108 malicious ads over 48 hours that redirected users to a ClickFix page prompting terminal commands to install malware.
Attackers gained control of the verified u/hbomax Reddit account and posted 108 malicious advertisements over a 48-hour period. The ads redirected users to hbomaxx[.]us, a site that mimicked HBO Max and displayed a download button that opened a ClickFix prompt. ADAMnetworks wrote, “The download button opened a ClickFix prompt that told the visitor to copy a command, open Terminal, paste the command, and run it. This transferred execution from the browser to a trusted system utility under the victim’s control.”
On macOS the prompt delivered curl | zsh commands that fetched and ran malicious code. Observed macOS payloads included MacSync, AMOS Helper and fake wallet applications that collected credentials, messages, browser data and cryptocurrency wallet information, and established persistence. On Windows the campaign used MSHTA and PowerShell to deliver Amatera Stealer and to install mechanisms intended to survive reboots. The Windows samples were configured for manual credential validation and masked command-and-control traffic by spoofing Facebook connections.
The operation also deployed clipboard replacement tools named AnimateClipper and ZigClipper to intercept cryptocurrency transfers and swap addresses when users pasted them. HudsonRock reported those clipboard stealers relied on a command-and-control channel hosted on a blockchain. Researchers say parts of the supporting infrastructure were created more than a year ago and have been reused in attacks since early 2026.
Security teams organized the ads into five lure groups and pushed them aggressively during the two-day window. Reddit was notified of the fraudulent activity and suspended the ads tied to the verified account. The account’s verified status made the ads appear legitimate and increased the likelihood that users would follow the download instructions. The incident shows how a compromised verified account can expand a brand’s social engineering attack surface, turning inherited trust into a malware distribution channel.
Warner Bros., owner of HBO Max, was contacted for comment. Investigators continue to monitor the PasteSwitch infrastructure and related malware strains.
Researchers recommend that users do not execute terminal commands copied from web pages, verify download sources, run endpoint protection to detect unusual process activity, check clipboard contents before sending cryptocurrency, and use wallets with protections against clipboard tampering.







