
Cybercriminals hijacked HBO Max’s verified Reddit account and used it to run malicious ads that tricked Windows and Mac users into infecting their own computers.
Hackers compromised HBO Max’s official Reddit account and turned the trusted profile into a launchpad for ClickFix attacks, using malicious ads to push information-stealing malware to Windows and macOS users.
Security researchers say the attackers used the verified HBO Max account to run more than 100 malicious ads over roughly 48 hours.
Some ads promoted what appeared to be an HBO Max app for macOS. Others advertised fake AI tools, developer software and Mac utilities, widening the pool of potential victims beyond HBO Max subscribers.
The malicious ads came from the real, verified account of a recognizable brand – precisely the kind of signal people use to decide whether to trust something online.
ClickFix is an increasingly popular social-engineering technique with an unusual characteristic: instead of exploiting a software vulnerability, attackers persuade victims to execute the malware themselves.
The lure might appear as a CAPTCHA, an error message, a software installation guide or instructions for fixing some supposed problem.
The victim is then told to copy a command and paste it into Windows Run, PowerShell or, on a Mac, Terminal.
That command may download and execute additional malicious code. Because the victim is willingly interacting with legitimate operating-system tools, the attack can sidestep some of the barriers people normally associate with downloading and opening a suspicious executable.
In the HBO Max campaign, one lure advertised a nonexistent native HBO Max application for macOS. Clicking the supposed download led victims to instructions telling them to open Terminal and paste a command.
Researchers have linked the activity to a broader cross-platform campaign dubbed PasteSwitch, which can switch between various lures, operating systems and malicious payloads depending on the victim.
According to The Register and BleepingComputer, researchers observed the campaign distributing information-stealing malware to infect Mac users, including MacSync and an AMOS-related payload.
MacSync can target browser credentials, Firefox profiles, Telegram information, Apple Notes and macOS passwords. Other parts of the campaign have promoted fake cryptocurrency wallet applications designed to steal recovery phrases.
Windows victims have also been targeted with ClickFix instructions involving PowerShell and other built-in tools, ultimately leading to information-stealing malware.
This is what makes ClickFix especially dangerous. There may be no obviously suspicious attachment. The attacker simply persuades the victim to become part of the infection chain.
Apple has begun addressing this type of social engineering directly.
Starting with macOS Tahoe 26.4, Macs include several protections aimed at attacks that persuade users to paste malicious commands into Terminal or execute harmful scripts.
For users who don't normally work in Terminal, macOS can display a warning when text copied from common attack vectors – including web browsers, email clients and messaging apps – is pasted into Terminal.
The message warns that scammers commonly persuade people to paste commands that can harm their Mac or compromise their privacy. Apple also uses XProtect to inspect activity triggered by pasted Terminal commands and can block known malicious commands and scripts.

Source: Mr. Macintosh (via MacRumors)
These defenses directly target a defining characteristic of ClickFix: persuading users to infect their Macs with their own hands.
But they're not foolproof. A warning can still be ignored in some circumstances, attackers continuously change their instructions, and social engineering succeeds precisely because victims are persuaded that unusual steps are necessary.
The HBO Max incident highlights a weakness that technical safeguards alone can't eliminate: trust.
The attackers didn't merely create a convincing fake HBO Max advertisement. They gained control of the company's verified Reddit presence and used that legitimacy to make their malicious ads more believable.
ClickFix takes things one step further by convincing victims to cross the final security barrier themselves.
So remember one simple rule: a website should not need you to paste mysterious commands into your computer to prove you're human, install an ordinary app or fix a browser problem.
When it does, close the page.
On topic:
Reddit Fined $20 million for children’s privacy failures
tags
Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.
View all posts