HBO Max Reddit account hijacked for 108 ClickFix ads (PasteSwitch stealers)
BleepingComputer (14 September 2026) reports that the verified Reddit account u/hbomax was hijacked and used to run about 108 malicious advertisements over roughly 48 hours. Ads used ClickFix social engineering (victims paste commands into Windows Run/PowerShell or macOS Terminal) and redirected to lookalike sites (including hbomaxx[.]us). Hudson Rock and ADAMnetworks link the activity to a broader campaign they call PasteSwitch delivering information stealers, loaders, crypto clippers, and fake wallets on Windows and macOS; one macOS chain referenced “AMOS helper” persistence under a .com.apple.accountsd-style directory. Some ads impersonated HBO Max; others pushed fake AI/developer/macOS utilities. BleepingComputer said HBO / Warner Bros. Discovery had not responded at publication. Distinct from prior desk ClickFix/EtherHiding cards. Primary/wire: BleepingComputer.
- Product
- n/a (Reddit advertising / social engineering; Windows and macOS endpoints)
- Versions
- n/a
- Exploited in Australia?
- unknown
- Patch to
- Treat unexpected Run/Terminal paste prompts as hostile; verify streaming-app installs from official stores; revoke sessions if you interacted with u/hbomax ads in the window
Primary: BleepingComputer — HBO Max Reddit ClickFix (14 Sep 2026)
