5 min read

Hackers hijack HBO Max Reddit account to spread malware

Filip TRUȚĂ

September 15, 2026

Hackers hijack HBO Max Reddit account to spread malware

Cybercriminals hijacked HBO Max’s verified Reddit account and used it to run malicious ads that tricked Windows and Mac users into infecting their own computers.

Key takeaways:

  • Hackers compromised HBO Max’s verified Reddit account and used it to distribute malicious ads
  • The campaign targeted both Windows and macOS users
  • Victims were instructed to copy and paste malicious commands into Windows tools or the macOS Terminal
  • The malware could steal passwords, browser data, cryptocurrency information and other sensitive data
  • See it as a major red flag if a website asks you to paste commands into Terminal, PowerShell or Windows Run
  • If you have already pasted the command, Bitdefender recommends running a full security scan
  • macOS 26.4 and newer versions include protections specifically designed to disrupt this kind of attack

Hackers compromised HBO Max’s official Reddit account and turned the trusted profile into a launchpad for ClickFix attacks, using malicious ads to push information-stealing malware to Windows and macOS users.

Security researchers say the attackers used the verified HBO Max account to run more than 100 malicious ads over roughly 48 hours.

Some ads promoted what appeared to be an HBO Max app for macOS. Others advertised fake AI tools, developer software and Mac utilities, widening the pool of potential victims beyond HBO Max subscribers.

The malicious ads came from the real, verified account of a recognizable brand – precisely the kind of signal people use to decide whether to trust something online.

ClickFix makes you do the dirty work

ClickFix is an increasingly popular social-engineering technique with an unusual characteristic: instead of exploiting a software vulnerability, attackers persuade victims to execute the malware themselves.

The lure might appear as a CAPTCHA, an error message, a software installation guide or instructions for fixing some supposed problem.

The victim is then told to copy a command and paste it into Windows Run, PowerShell or, on a Mac, Terminal.

That command may download and execute additional malicious code. Because the victim is willingly interacting with legitimate operating-system tools, the attack can sidestep some of the barriers people normally associate with downloading and opening a suspicious executable.

In the HBO Max campaign, one lure advertised a nonexistent native HBO Max application for macOS. Clicking the supposed download led victims to instructions telling them to open Terminal and paste a command.

Researchers have linked the activity to a broader cross-platform campaign dubbed PasteSwitch, which can switch between various lures, operating systems and malicious payloads depending on the victim.

Passwords, accounts and crypto in the crosshairs

According to The Register and BleepingComputer, researchers observed the campaign distributing information-stealing malware to infect Mac users, including MacSync and an AMOS-related payload.

MacSync can target browser credentials, Firefox profiles, Telegram information, Apple Notes and macOS passwords. Other parts of the campaign have promoted fake cryptocurrency wallet applications designed to steal recovery phrases.

Windows victims have also been targeted with ClickFix instructions involving PowerShell and other built-in tools, ultimately leading to information-stealing malware.

This is what makes ClickFix especially dangerous. There may be no obviously suspicious attachment. The attacker simply persuades the victim to become part of the infection chain.

Apple is making ClickFix harder on Macs

Apple has begun addressing this type of social engineering directly.

Starting with macOS Tahoe 26.4, Macs include several protections aimed at attacks that persuade users to paste malicious commands into Terminal or execute harmful scripts.

For users who don't normally work in Terminal, macOS can display a warning when text copied from common attack vectors – including web browsers, email clients and messaging apps – is pasted into Terminal.

The message warns that scammers commonly persuade people to paste commands that can harm their Mac or compromise their privacy. Apple also uses XProtect to inspect activity triggered by pasted Terminal commands and can block known malicious commands and scripts.

Source: Mr. Macintosh (via MacRumors)

These defenses directly target a defining characteristic of ClickFix: persuading users to infect their Macs with their own hands.

But they're not foolproof. A warning can still be ignored in some circumstances, attackers continuously change their instructions, and social engineering succeeds precisely because victims are persuaded that unusual steps are necessary.

How to protect yourself from ClickFix attacks

  • The safest response remains simple: if a website unexpectedly asks you to open Terminal and paste a command, don't!
  • ClickFix relies heavily on persuasion, which means recognizing the trick can stop the attack before malware ever reaches your device.
  • Never paste commands from a website into Terminal, PowerShell, Command Prompt or Windows Run unless you fully understand what they do.
  • CAPTCHAs, streaming services and ordinary websites don't need you to execute system commands to prove you're human, fix your browser or install an app.
  • Be especially suspicious when a page gives you step-by-step keyboard instructions, tells you to copy something you can't understand, or claims the procedure is required to fix an error.
  • Don't assume an ad is safe because it comes from a verified account. The HBO Max incident shows why. Legitimate social media profiles can be compromised and used to borrow the credibility of the real organization behind them.
  • Download software from official sources. Instead of following an advertisement or sponsored search result, navigate independently to the developer's official website or use a trusted app store.
  • Keep your operating system and security software updated. Mac users should install the latest available macOS updates to benefit from Apple's newer Terminal and script protections. Windows users should likewise keep Windows and Microsoft Defender – or their chosen security solution – current.
  • And don't override a security warning simply because a website tells you to. If macOS says “Possible malware, Paste blocked,” that's your cue to stop and reconsider what you're being asked to do. Apple explicitly advises users not to proceed unless they're certain what the command does and where it came from.

What if you already pasted the command?

  • If you followed suspicious instructions and executed a command, disconnecting from the malicious page isn't necessarily enough – the command may already have downloaded or launched malware.
  • Run a full security scan immediately with Bitdefender Total Security.
  • If you suspect malware or information-stealing activity, change important passwords from a clean device, starting with your primary email account, password manager, banking and other high-value services.
  • Revoke unfamiliar sessions where possible and enable multi-factor authentication or passkeys.
  • Cryptocurrency users should treat exposed wallet credentials or recovery phrases seriously. A stolen seed phrase cannot simply be reset like a password.

Bottom line

The HBO Max incident highlights a weakness that technical safeguards alone can't eliminate: trust.

The attackers didn't merely create a convincing fake HBO Max advertisement. They gained control of the company's verified Reddit presence and used that legitimacy to make their malicious ads more believable.

ClickFix takes things one step further by convincing victims to cross the final security barrier themselves.

So remember one simple rule: a website should not need you to paste mysterious commands into your computer to prove you're human, install an ordinary app or fix a browser problem.

When it does, close the page.

On topic:

Reddit Fined $20 million for children’s privacy failures

The scam that tricks you into infecting your own Mac

Instagram creators hit by ransom demands

tags


Author


Filip TRUȚĂ

Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.

View all posts

You might also like

Bookmarks


loader