Hackers hijack HBO Max’s verified Reddit account to spread infostealer malware
A verified Reddit account gave hackers the perfect cover for a sophisticated ClickFix campaign.

Image by Hudson Rock
- Hackers used HBO Max’s verified Reddit account to post 108 malicious ads over 48 hours.
- Fake ads led users to lookalike pages that tried to trick them into installing malware.
- Researchers say the campaign targeted macOS and Windows users with fake apps, developer tools, and disk cleaners.
- A Reddit administrator shut down the malicious campaign after it ran for at least two days.
Hackers, after compromising HBO Max’s official Reddit account, planted over a hundred fake ads on the site – all to trick users who clicked on them into installing malware.
New research published on Monday and spearheaded by Alon Gal, founder and CTO of Hudson Rock, says the latest HBO Max ClickFix campaign was running amok for at least 2 days before a Reddit administrator was able to shut it down.
“For 48 hours, the verified HBO Max Reddit account was weaponized to blast 108 malicious ads across the platform, running an evasive cross-platform Clickfix operation we called PasteSwitch,” Gal said in a LinkedIn post about the latest find.
Additionally, it seemed no platform was immune to the campaign, which reportedly “spanned macOS stealers, Windows loaders, deceptive TLS tactics, and contract-controlled cryptocurrency clippers.”
It also appeared the operation was chock-full of duplicitous tactics, warned Gal and his co-collaborator Kirk from ADAMnetworks, who published a separate blog about the PasteSwitch operation on Monday.
The September payload was able to collect Chromium and Firefox credentials and cookies, Keychain material, Apple Notes, shell history, SSH material, wallet data, messenger data, password-manager data, and selected files,said Kirk, threat researcher and security analyst at ADAMnetworks.
Infostealing malware – which Gal says has compromised tens of millions of computers to date – is designed to steal user credentials, cookies, documents, browsing history, and a host of other sensitive data.
HBO Max ads hide malware campaign
The researchers said they first became aware of the malicious behavior after one "vigilant" Redditor began interacting with the fake ads – which sent them to a fraudulent site mimicking a real HBO Max ad one might encounter on the verified “u/hbomax” account.
The Redditor reported the malicious activity to HBO, Reddit, and on a cybersecurity subreddit, prompting the researchers to launch an investigation.
The setup was meant to hit users with a double whammy – first by compromising the real HBO Max account and then by creating "highly polished" and convincing ads – allowing the hackers to “bypass the initial skepticism many users apply to internet advertisements.”
Not only that, the bad actor was said to have “squeezed as much value as possible out of the verified account’s status, pivoting quickly when domains were burned."
The research tracked a total of 108 ads across five lure groups during the 48-hour window, promoting items such as fake software, a nonexistent macOS HBO Max app, developer AI tools, and disk cleaners.
More than 40 ads were HBO Max-themed, 36 promoted OpenAI Codex downloads, and the rest were split between a macOS disk utility and desktop developer tools.
What happens when users click?
It all begins with the victim clicking the false advertisement, but before the infostealer launches, the attacker must still convince the unsuspecting user to carry out several more steps.
Instead of simply clicking a download button to install malware, the site deploys the PasteSwitch ClickFix overlay – essentially, an instruction page asking the victim to copy an attacker-controlled command and paste and run it on their own computer.
This tricks the victim into executing malicious code themselves, often bypassing a browser's standard security guardrails, the researchers explained.
Once they paste and execute that command, PasteSwitch takes over.
At this point, the attacker’s infrastructure determines the victim's operating system and which campaign lure they chose, routing them to the appropriate malicious payload.
Another advanced tactic Gal revealed was that PasteSwitch kept its visible lures disposable while preserving operational structure, as the “destination domains, copied commands, and payload infrastructure remained under attacker control.”
Recovered pages and payloads showed separate services for lures, visitor qualification, staging, telemetry, payload delivery, C2, and exfiltration,said Alon Gal, founder and CTO of Hudson Rock.
The research discovered that the attacker could simply swap out lures or domains if they were burned, blocked, or stopped working – all without having to recreate the entire backend infrastructure.
The name PasteSwitch was chosen because it describes the exact moment when the delivery system automatically “switches” among the platform, campaign, payload, and monetization branches, Gal said.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.