Sophia
Hart

HBO Max Reddit Account Hijack: ClickFix Ads Push Windows and macOS Infostealers

Sophia Hart

Sep 16, 2026

5 min read

hbo max reddit account hijack

TL; DR

  • Hackers compromised HBO Max’s verified Reddit account and ran 108 malicious ads in about 48 hours, per Hudson Rock and ADAMnetworks.
  • The ads used ClickFix social engineering, prompting Windows and macOS users to paste commands into Run, PowerShell, or Terminal.
  • macOS payloads included MacSync credential theft and AMOS malware persistence, while Windows chains disabled AMSI and loaded Amatera Stealer in memory.
  • Researchers linked the campaign to a broader operation called PasteSwitch, which also pushed fake AI tools, developer software, and crypto wallet apps.

Attackers compromised HBO Max’s verified Reddit account and used it to run malicious advertisements. Hudson Rock and ADAMnetworks reported that the HBO Max Reddit account hijack launched 108 ads over roughly 48 hours. The ads relied on ClickFix malware tactics, tricking Windows and macOS users into pasting commands into Run, PowerShell, or Terminal.

Some ads impersonated HBO Max directly. Others promoted fake AI tools, developer software, and macOS utilities, widening the pool of potential victims well beyond streaming subscribers. Enterprises should pay attention because this pattern turns a trusted brand account into a distribution channel for infostealer malware on managed endpoints.

Book a free demo and explore Hexnode today!

How the hijacked account delivered ClickFix ads

The compromised account gave attackers a verified, trusted identity to push ads at scale before anyone noticed.

  • The verified u/hbomax Reddit account posted ads promoting a fake native HBO Max app for macOS, redirecting visitors to lookalike sites such as hbomaxx[.]us.
  • HBO Max does not offer an official native macOS desktop app; the service is accessed through a browser or, on Apple Silicon Macs, by running its iPadOS app. This made the advertised “macOS app” inherently suspicious, since no legitimate version exists to imitate.
  • Separate ads under the same account promoted unrelated lures, including fake AI and developer tools, a macOS “clean disk” utility, and other software.
  • Clicking the download button on these sites did not deliver a file. It displayed ClickFix instructions telling visitors to open Terminal or Windows Run and paste a command.
  • Hudson Rock and ADAMnetworks counted 40 ads pointing to hbomaxx[.]app, 36 to a fake AI/developer site, and additional smaller batches to other domains.
  • After the campaign was reported, a Reddit admin paused the ads and referred the account to Reddit’s Security and Safety teams.

Payload behavior on macOS and Windows

Once a victim pasted the command, the attack diverged into separate chains depending on the operating system.

macOS:

  • A Base64-encoded Terminal command fetched a shell script from attacker infrastructure, which Hudson Rock tied to the PasteSwitch campaign’s September delivery activity.
  • MacSync malware stole browser credentials, Firefox profiles, Telegram data, Apple Notes content, and macOS passwords.
  • A separate chain installed an AMOS malware helper that persisted through a hidden directory and enrolled the device for further attacker tasking.
  • Fake Ledger, Trezor Suite, and Exodus wallet apps targeted victims’ wallet recovery phrases.

Windows:

  • ClickFix instructions triggered a Windows PowerShell attack chain using mshta to launch execution.
  • One chain used an MP3/HTA polyglot file to create a scheduled task, launch 32-bit PowerShell, and disable Microsoft’s Antimalware Scan Interface (AMSI).
  • The backend generated victim-specific infrastructure based on the target’s computer name and username.
  • Later stages used obfuscated PowerShell and shellcode to load Amatera Stealer directly into memory without writing the final payload to disk.
  • Once active, Amatera Stealer used TLS SNI spoofing, presenting its command-and-control traffic as a connection to facebook.com. This let it evade network filtering that relies on inspecting the SNI field to identify malicious destinations.
  • The broader PasteSwitch operation has also pushed clipboard-hijacking tools, AnimateClipper and ZigClipper, to intercept cryptocurrency transactions; public reporting does not specify which platform these target.

Payload Overview

Payload / Technique Platform Operational Risk
MacSync macOS Steals browser credentials, Telegram data, and Apple Notes content
AMOS malware helper macOS Establishes persistence and enrolls devices for further tasking
Amatera Stealer Windows Loads in memory, evading disk-based detection
AMSI bypass + scheduled task creation Windows Attack technique enabling stealthy PowerShell execution during the chain
AnimateClipper / ZigClipper Not specified in public reporting Hijacks clipboard contents to redirect cryptocurrency transfers

Where Hexnode fits

ClickFix attacks rely on native operating system tools, which puts the emphasis on endpoint visibility rather than download scanning.

Detection and containment (XDR):

  • Hexnode XDR now covers Windows and macOS endpoints, giving admins one console to investigate suspicious PowerShell, mshta, or Terminal activity consistent with ClickFix execution.
  • When XDR flags a suspicious process chain, admins can isolate or quarantine the affected endpoint directly from the console to limit further spread.

Prevention at the endpoint (UEM):

  • Hexnode UEM lets admins enforce native Application Restrictions and AppLocker policies to block unauthorized executables from launching, giving IT a way to restrict unwanted software from running.

What Hexnode doesn’t cover:

Hexnode does not detect specific malware families like MacSync or Amatera Stealer, patch third-party browsers or wallet apps, or monitor Reddit or ad-platform account activity. Those controls remain with the affected vendors and the organization’s account-security team.

cybersecurity framework

Building a cybersecurity framework for your enterprise

Explore common cybersecurity framework types and how UEM strengthens organizational defenses against network penetration.

DOWNLOAD

FAQs

ClickFix tricks users into pasting a malicious command into Run, PowerShell, or Terminal. Since the user runs it themselves with legitimate tools, it can evade some browser and download defenses.

Public reporting does not confirm a breach of HBO Max’s core systems. Attackers compromised its verified Reddit account. Warner Bros. Discovery had not responded to questions at the time of reporting.

Review whether employees clicked HBO Max, AI tool, or macOS app ads during the campaign window. Check endpoint logs for PowerShell, mshta, or Terminal activity matching the chains above.

Conclusion

The HBO Max Reddit account hijack shows how a single compromised social account can distribute infostealer malware to a wide, untargeted audience. ClickFix ads work because they turn the victim into the execution engine, using trusted operating system tools instead of a traditional download.

Enterprises need endpoint visibility across Windows and macOS, script execution controls, and clear governance over brand and advertising accounts. No single control removes this risk entirely, but layered detection and response narrows the window attackers have to operate.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.