Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack
A threat actor compromised the official HBO Max Reddit account and used it to run a malvertising campaign that directed macOS and Windows users to a fake HBO Max site. The site prompted users to execute commands that installed malware designed to steal credentials, messages, browser data, and cryptocurrency wallet information, and maintain persistence. The campaign, active for 48 hours, used multiple malware families including MacSync, AMOS Helper, Amatera Stealer, AnimateClipper, and ZigClipper. Clipboard stealers replaced cryptocurrency addresses to divert transactions. Reddit suspended the malicious ads after notification.
AI Analysis
Technical Summary
Attackers hijacked the verified HBO Max Reddit account to push 108 malicious ads over 48 hours, leading users to a ClickFix landing page mimicking HBO Max. The page tricked macOS users into running curl | zsh commands and Windows users into executing MSHTA and PowerShell scripts, delivering malware such as MacSync, AMOS Helper, Amatera Stealer, and clipboard hijackers AnimateClipper and ZigClipper. The malware stole sensitive information including credentials and cryptocurrency wallet data, and maintained persistence. The malware communicated with command-and-control servers, some hosted on blockchain infrastructure. The campaign, tracked as PasteSwitch, was active since early 2026 and used advanced evasion techniques. Reddit removed the malicious ads promptly after being alerted.
Potential Impact
The campaign enabled attackers to steal sensitive user information including credentials, messages, browser data, and cryptocurrency wallet details from both macOS and Windows users. It also allowed persistent access to infected machines and hijacked cryptocurrency transactions by replacing wallet addresses. The use of trusted system utilities for execution and blockchain-hosted command-and-control infrastructure increased the stealth and resilience of the malware. The compromise of a verified Reddit account lent credibility to the malicious ads, increasing the risk of user compromise.
Mitigation Recommendations
Reddit has suspended the malicious advertisements associated with the compromised HBO Max account. Users should avoid executing commands from untrusted sources, especially those prompting terminal or PowerShell commands. Since this attack relies on social engineering via a compromised account, monitoring for suspicious ads and verifying official sources is critical. No official patch or fix applies as this is a social engineering and malware delivery campaign. Users should ensure endpoint security solutions are updated to detect related malware families. Warner Bros. and Reddit should investigate and secure the compromised account to prevent recurrence.
Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack
Description
A threat actor compromised the official HBO Max Reddit account and used it to run a malvertising campaign that directed macOS and Windows users to a fake HBO Max site. The site prompted users to execute commands that installed malware designed to steal credentials, messages, browser data, and cryptocurrency wallet information, and maintain persistence. The campaign, active for 48 hours, used multiple malware families including MacSync, AMOS Helper, Amatera Stealer, AnimateClipper, and ZigClipper. Clipboard stealers replaced cryptocurrency addresses to divert transactions. Reddit suspended the malicious ads after notification.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Attackers hijacked the verified HBO Max Reddit account to push 108 malicious ads over 48 hours, leading users to a ClickFix landing page mimicking HBO Max. The page tricked macOS users into running curl | zsh commands and Windows users into executing MSHTA and PowerShell scripts, delivering malware such as MacSync, AMOS Helper, Amatera Stealer, and clipboard hijackers AnimateClipper and ZigClipper. The malware stole sensitive information including credentials and cryptocurrency wallet data, and maintained persistence. The malware communicated with command-and-control servers, some hosted on blockchain infrastructure. The campaign, tracked as PasteSwitch, was active since early 2026 and used advanced evasion techniques. Reddit removed the malicious ads promptly after being alerted.
Potential Impact
The campaign enabled attackers to steal sensitive user information including credentials, messages, browser data, and cryptocurrency wallet details from both macOS and Windows users. It also allowed persistent access to infected machines and hijacked cryptocurrency transactions by replacing wallet addresses. The use of trusted system utilities for execution and blockchain-hosted command-and-control infrastructure increased the stealth and resilience of the malware. The compromise of a verified Reddit account lent credibility to the malicious ads, increasing the risk of user compromise.
Defensive Guidance
Reddit has suspended the malicious advertisements associated with the compromised HBO Max account. Users should avoid executing commands from untrusted sources, especially those prompting terminal or PowerShell commands. Since this attack relies on social engineering via a compromised account, monitoring for suspicious ads and verifying official sources is critical. No official patch or fix applies as this is a social engineering and malware delivery campaign. Users should ensure endpoint security solutions are updated to detect related malware families. Warner Bros. and Reddit should investigate and secure the compromised account to prevent recurrence.
Technical Details
- Classification
- {"confidence":0.65,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/hacked-hbo-reddit-account-used-for-malware-delivery-via-clickfix-attack/","fetched":true,"fetchedAt":"2026-09-15T09:16:36.378Z","wordCount":990}
Threat ID: 6aa90cf455bf5e2cf5959643
Added to database: 09/15/2026, 09:16:36 UTC
Last enriched: 09/15/2026, 09:16:46 UTC
Last updated: 09/15/2026, 09:16:46 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.