ADVERTISEMENT

Hackers hijack HBO Max’s verified Reddit account to spread infostealer malware

A verified Reddit account gave hackers the perfect cover for a sophisticated ClickFix campaign.

HBO Max PasteSwitch ClickFix

Image by Hudson Rock

Stefanie Schappert
Stefanie Schappert Senior Journalist
September 15, 2026 Updated: 31 seconds ago 3 min read
Key takeaways:
The September payload was able to collect Chromium and Firefox credentials and cookies, Keychain material, Apple Notes, shell history, SSH material, wallet data, messenger data, password-manager data, and selected files,
said Kirk, threat researcher and security analyst at ADAMnetworks.

HBO Max ads hide malware campaign

HBOMacClickfix4
Fake HBO Max ad redirects users to a malicious site designed to trick them into installing malware. Image by Hudson Rock
ADVERTISEMENT
HBOMacClickfixlure
Researchers tracked 108 malicious Reddit ads across five lure groups during the 48-hour campaign. Image by Hudson Rock.

What happens when users click?

HBOMacClickfix2
PasteSwitch instructs victims to copy and paste an attacker-supplied command into their device terminal. Images by Hudson Rock.
Recovered pages and payloads showed separate services for lures, visitor qualification, staging, telemetry, payload delivery, C2, and exfiltration,
said Alon Gal, founder and CTO of Hudson Rock.
Stefanie Schappert
Senior Journalist
ADVERTISEMENT