Skip to main content

Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack

0
High
Published: 09/15/2026 (09/15/2026, 09:09:00 UTC)
Source: SecurityWeek

Description

A threat actor compromised the official HBO Max Reddit account and used it to run a malvertising campaign that directed macOS and Windows users to a fake HBO Max site. The site prompted users to execute commands that installed malware designed to steal credentials, messages, browser data, and cryptocurrency wallet information, and maintain persistence. The campaign, active for 48 hours, used multiple malware families including MacSync, AMOS Helper, Amatera Stealer, AnimateClipper, and ZigClipper. Clipboard stealers replaced cryptocurrency addresses to divert transactions. Reddit suspended the malicious ads after notification.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/15/2026, 09:16:46 UTC

Technical Analysis

Attackers hijacked the verified HBO Max Reddit account to push 108 malicious ads over 48 hours, leading users to a ClickFix landing page mimicking HBO Max. The page tricked macOS users into running curl | zsh commands and Windows users into executing MSHTA and PowerShell scripts, delivering malware such as MacSync, AMOS Helper, Amatera Stealer, and clipboard hijackers AnimateClipper and ZigClipper. The malware stole sensitive information including credentials and cryptocurrency wallet data, and maintained persistence. The malware communicated with command-and-control servers, some hosted on blockchain infrastructure. The campaign, tracked as PasteSwitch, was active since early 2026 and used advanced evasion techniques. Reddit removed the malicious ads promptly after being alerted.

Potential Impact

The campaign enabled attackers to steal sensitive user information including credentials, messages, browser data, and cryptocurrency wallet details from both macOS and Windows users. It also allowed persistent access to infected machines and hijacked cryptocurrency transactions by replacing wallet addresses. The use of trusted system utilities for execution and blockchain-hosted command-and-control infrastructure increased the stealth and resilience of the malware. The compromise of a verified Reddit account lent credibility to the malicious ads, increasing the risk of user compromise.

Defensive Guidance

Reddit has suspended the malicious advertisements associated with the compromised HBO Max account. Users should avoid executing commands from untrusted sources, especially those prompting terminal or PowerShell commands. Since this attack relies on social engineering via a compromised account, monitoring for suspicious ads and verifying official sources is critical. No official patch or fix applies as this is a social engineering and malware delivery campaign. Users should ensure endpoint security solutions are updated to detect related malware families. Warner Bros. and Reddit should investigate and secure the compromised account to prevent recurrence.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.65,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/hacked-hbo-reddit-account-used-for-malware-delivery-via-clickfix-attack/","fetched":true,"fetchedAt":"2026-09-15T09:16:36.378Z","wordCount":990}

Threat ID: 6aa90cf455bf5e2cf5959643

Added to database: 09/15/2026, 09:16:36 UTC

Last enriched: 09/15/2026, 09:16:46 UTC

Last updated: 09/15/2026, 09:16:46 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses