Official HBO Max Reddit Account Compromised to Spread Infostealer Malware Through Malvertising

Views: 38 views

508/69 Wednesday, September 16, 2026

Reports indicate that the official verified Reddit account of the HBO Max streaming service was compromised by threat actors and used to distribute more than one hundred malware-laced advertisements. The campaign targeted users on both Windows and macOS. The attackers shifted their tactics to abuse the credibility of official social media accounts as a distribution and deception channel at scale. Users who interacted with the advertisements were at high risk of system compromise and theft of sensitive personal information.

Cybersecurity researchers identified the campaign as PasteSwitch, which uses a social engineering technique known as ClickFix. The attackers created fake websites claiming to offer an HBO Max application for Mac, while also impersonating other software such as developer tools and disk cleaning utilities. When users clicked the download button on the fake websites, they were shown deceptive instructions directing them to copy and paste commands into Terminal. If users followed the instructions, malware would be installed on their systems immediately. The malware observed included infostealers, cryptocurrency wallet address clippers, and loader malware. The attackers also used blockchain-based technology to manage command-and-control server domains in an attempt to evade takedown. Reddit has reportedly suspended the display of the advertisements and is investigating the incident.

In response to this incident, users and administrators should exercise caution when interacting with advertisements or links that encourage software downloads, even if the content appears to come from a verified account. The most important precaution is to never copy and paste unknown commands into Terminal or Command Prompt. Users should download software or applications only from the official websites of developers. For enterprise network administrators, it is recommended to monitor for unusual command execution within systems and track or block access to malicious domains associated with ClickFix techniques to reduce the risk of cyberattacks.

Source: https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408