108 Malicious Ads: Hackers Hijack HBO Max Reddit for ClickFix
Cyber defenders are tracking PasteSwitch, a malvertising campaign that abused HBO Max's verified Reddit account to push 108 ClickFix ads landing on hbomaxx[.]us. The operation dropped macOS and Windows info-stealers via curl|zsh and MSHTA/PowerShell, then used clipboard clippers to steal crypto.
Beat this week
Last 7 days · Threat Intelligence
Impact 6.2/10 (-0.2 vs prior). Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 35 percentage points.
This story sits in Threat Intelligence — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
Cybersecurity briefing
Key takeaways
- Cyber defenders are tracking PasteSwitch, a malvertising campaign that abused HBO Max's verified Reddit account to push 108 ClickFix ads landing on hbomaxx[.]us.
- The operation dropped macOS and Windows info-stealers via curl|zsh and MSHTA/PowerShell, then used clipboard clippers to steal crypto.
- BleepingComputer
- SecurityWeek
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1Hackers hijacked the verified u/hbomax Reddit account and used it to launch 108 malicious advertisements over approximately 48 hours.
- 2The campaign is tracked as PasteSwitch and spanned five lure groups, targeting both Windows and macOS users.
- 3Clicking malicious ads led to hbomaxx[.]us, a fake HBO Max site featuring a download button for a non-existent native macOS app.
- 4macOS payloads were delivered via curl | zsh and included MacSync, AMOS Helper, and fake wallet apps that steal credentials, messages, browser data, and crypto wallets while establishing persistence.
- 5Windows payloads used MSHTA and PowerShell to deliver Amatera Stealer, which spoofed Facebook connections to hide command-and-control traffic.
- 6PasteSwitch also deploys AnimateClipper and ZigClipper to replace cryptocurrency addresses, with C&C hosted on blockchain infrastructure likely set up over a year ago.
The download button opened a ClickFix prompt that told the visitor to copy a command, open Terminal, paste the command, and run it. This transferred execution from the browser to a trusted system utility under the victim's control.
Analysis of the PasteSwitch ClickFix landing page
Who's Affected
Analysis
For threat hunters and SOC analysts, the HBO Max Reddit hijack is less a brand-safety story than a live demonstration of ClickFix's detection gap. The campaign's move from browser to native shell via curl | zsh and MSHTA/PowerShell means classic file-reputation controls will not catch the compromise. Tracking the PasteSwitch operation requires command-line telemetry, unusual ad-platform account behavior, and visibility into blockchain-backed C2.
The compromise of HBO Max's verified u/hbomax Reddit account and its use to push 108 malicious advertisements over roughly 48 hours represents a new escalation in malvertising and social-engineering tradecraft. Security researchers from Hudson Rock and ADAMnetworks tied the abuse to a tracked operation called PasteSwitch, which used the trusted streaming brand to drive Reddit users to a fake HBO Max site, hbomaxx[.]us. Instead of relying on a drive-by exploit or a malicious file attachment, the operation's landing page deployed ClickFix, a technique in which visitors are shown a fake error, CAPTCHA, or download prompt and instructed to copy a command from the browser and paste it into Windows Run, PowerShell, or macOS Terminal. That manual step shifts execution from the browser into a legitimate operating-system interpreter under the victim's own account, allowing attackers to sidestep browser-based blocklists, download scanning, and many endpoint controls that key on malicious file provenance.
Security researchers from Hudson Rock and ADAMnetworks tied the abuse to a tracked operation called PasteSwitch, which used the trusted streaming brand to drive Reddit users to a fake HBO Max site, hbomaxx[.]us.
ClickFix is not new, but its rise reflects how effectively attackers have adapted to improved browser defenses and user training. The ADAMnetworks description of the download button is instructive: clicking it opened a ClickFix prompt that told the visitor to copy a command, open Terminal, paste it, and run it. This action transferred execution from the browser to a trusted system utility that the victim controlled. In the PasteSwitch instance, macOS victims were fed a curl | zsh pipeline, a command pattern that fetches a remote script and executes it locally. The resulting payloads included MacSync, AMOS Helper, fake cryptocurrency wallet applications, and additional information-stealing code. The researchers reported that the malware sought credentials, messages, browser data, and cryptocurrency wallet information, and attempted to establish persistence on the infected machines. Because the download appears to be a native HBO Max macOS application—an application that does not exist—the bait targeted users who might reasonably trust a verified brand account and expect such an app.
Windows victims were handled with a different but equally familiar execution chain. The campaign used MSHTA and PowerShell to deliver Amatera Stealer, a credential and information stealer configured for manual credential validation. The malware attempted to evade network telemetry by spoofing Facebook connections to obscure its command-and-control communications. This dual-channel approach—native macOS scripting on one side and Microsoft-signed script hosts on the other—lets PasteSwitch target almost any consumer or employee who can be convinced to paste a command. It also complicates detection because legitimate administrative workflows can involve the same system utilities.
The larger PasteSwitch operation goes beyond initial access. Hudson Rock and ADAMnetworks found the attackers deployed AnimateClipper and ZigClipper as persistent clipboard replacement tools, swapping cryptocurrency destination addresses at the moment a victim attempts a transaction. The attackers hosted C&C infrastructure on a blockchain, making takedown and sinkholing considerably harder than a conventional domain or IP. The researchers assessed that the infrastructure was likely established more than a year ago and has been used in attacks since early 2026, suggesting a sustained campaign with reusable tooling rather than a one-off compromise. The 108 ads were spread across five lure groups, implying methodical A/B testing of impersonations and fake software.
For security teams, there are several implications. First, verification on Reddit or any social platform does not equal account security. A compromised corporate social account can amplify malicious content to a large, trusted audience while evading suspicion. Second, detection approaches that focus on downloaded files will miss ClickFix attacks because no malicious file crosses the browser boundary; the dangerous activity is the pasted command. Organizations should restrict execution of curl, zsh, PowerShell, and MSHTA where possible, monitor command-line telemetry for suspicious paste-and-run patterns, and train users that legitimate vendors will never ask them to paste commands to fix an error or verify a CAPTCHA. Third, brand impersonation extends beyond email to social advertising, and companies should monitor both their accounts and impersonating domains with the same urgency as phishing.
What to Watch
The incident also highlights a growing convergence of malvertising, social engineering, and cryptocurrency theft. The use of clipboard clippers and fake wallets points to an economic motive centered on crypto users, but the information stealers could also enable long-term credential theft, session-token hijacking, and supply-chain pivots if corporate accounts are compromised. Reddit has been notified of the malicious activity, and BleepingComputer reported that HBO and Warner Bros. Discovery had not responded to questions at the time of publication. That silence leaves unclear whether the HBO Max Reddit account was protected by multi-factor authentication, whether session tokens were stolen via an infostealer on an employee device, or whether the account was accessed through a third-party social media management tool. The investigation is likely to continue.
Forward-looking, the PasteSwitch campaign should be treated as an active and adaptable threat. Its blend of cross-platform ClickFix delivery, persistent clipboard theft, and blockchain-hosted C2 means defenders cannot rely on a single control or blocklist. Expect the operators to continue rotating lures, brands, and payloads, and expect other groups to copy the playbook. Monitoring for newly registered lookalike domains, unusual verified-account advertisements, and command-line execution patterns such as curl | zsh or mshta.exe followed by paste events should be priorities. The most effective immediate mitigation is user education focused on the one action that makes ClickFix possible: pasting attacker-supplied commands into a trusted system shell.
Source cluster
Primary reporting
Cite This Page
"108 Malicious Ads: Hackers Hijack HBO Max Reddit for ClickFix." Cyber Intelligence Brief, September 15, 2026. https://getcyberbrief.com/story/hacked-hbo-max-reddit-clickfix-pasteswitch-campaign
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |