{"id":1688,"date":"2026-09-16T14:53:34","date_gmt":"2026-09-16T09:23:34","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1688"},"modified":"2026-09-18T10:29:28","modified_gmt":"2026-09-18T04:59:28","slug":"hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/","title":{"rendered":"HBO Max Reddit Account Hijack: ClickFix Ads Push Windows and macOS Infostealers"},"content":{"rendered":"<p>Attackers compromised HBO Max&#8217;s verified Reddit account and used it to run malicious advertisements. Hudson Rock and ADAMnetworks reported that the HBO Max Reddit account hijack launched 108 ads over roughly 48 hours. The ads relied on ClickFix malware tactics, tricking Windows and macOS users into pasting commands into Run, PowerShell, or Terminal.<\/p>\n<p>Some ads impersonated HBO Max directly. Others promoted fake AI tools, developer software, and macOS utilities, widening the pool of potential victims well beyond streaming subscribers. Enterprises should pay attention because this pattern turns a trusted brand account into a distribution channel for infostealer <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-malware\/\">malware<\/a> on managed endpoints.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How the hijacked account delivered ClickFix ads<\/h2>\n<p>The compromised account gave attackers a verified, trusted identity to push ads at scale before anyone noticed.<\/p>\n<ul>\n<li>The verified u\/hbomax Reddit account posted ads promoting a fake native HBO Max app for macOS, redirecting visitors to lookalike sites such as hbomaxx[.]us.<\/li>\n<li>HBO Max does not offer an official native macOS desktop app; the service is accessed through a browser or, on Apple Silicon Macs, by running its iPadOS app. This made the advertised &#8220;macOS app&#8221; inherently suspicious, since no legitimate version exists to imitate.<\/li>\n<li>Separate ads under the same account promoted unrelated lures, including fake AI and developer tools, a macOS &#8220;clean disk&#8221; utility, and other software.<\/li>\n<li>Clicking the download button on these sites did not deliver a file. It displayed ClickFix instructions telling visitors to open Terminal or Windows Run and paste a command.<\/li>\n<li>Hudson Rock and ADAMnetworks counted 40 ads pointing to hbomaxx[.]app, 36 to a fake AI\/developer site, and additional smaller batches to other domains.<\/li>\n<li>After the campaign was reported, a Reddit admin paused the ads and referred the account to Reddit&#8217;s Security and Safety teams.<\/li>\n<\/ul>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/threat-classification.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>What is Threat Classification?<\/h4><p>Threat classification organizes security threats by type, severity, and impact.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/what-is-threat-classification\/\" aria-label=\"What is Threat Classification?\"><\/a><\/div><\/div><\/div>\n<h2>Payload behavior on macOS and Windows<\/h2>\n<p>Once a victim pasted the command, the attack diverged into separate chains depending on the operating system.<\/p>\n<h3>macOS:<\/h3>\n<ul>\n<li>A Base64-encoded Terminal command fetched a shell script from attacker infrastructure, which Hudson Rock tied to the PasteSwitch campaign&#8217;s September delivery activity.<\/li>\n<li>MacSync malware stole browser credentials, Firefox profiles, Telegram data, Apple Notes content, and macOS passwords.<\/li>\n<li>A separate chain installed an AMOS malware helper that persisted through a hidden directory and enrolled the device for further attacker tasking.<\/li>\n<li>Fake Ledger, Trezor Suite, and Exodus wallet apps targeted victims&#8217; wallet recovery phrases.<\/li>\n<\/ul>\n<h3>Windows:<\/h3>\n<ul>\n<li>ClickFix instructions triggered a Windows PowerShell <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-attack-chain\/\">attack chain<\/a> using mshta to launch execution.<\/li>\n<li>One chain used an MP3\/HTA polyglot file to create a scheduled task, launch 32-bit PowerShell, and disable Microsoft&#8217;s Antimalware Scan Interface (AMSI).<\/li>\n<li>The backend generated victim-specific infrastructure based on the target&#8217;s computer name and username.<\/li>\n<li>Later stages used obfuscated PowerShell and shellcode to load Amatera Stealer directly into memory without writing the final payload to disk.<\/li>\n<li>Once active, Amatera Stealer used TLS SNI spoofing, presenting its command-and-control traffic as a connection to facebook.com. This let it evade network filtering that relies on inspecting the SNI field to identify malicious destinations.<\/li>\n<li>The broader PasteSwitch operation has also pushed clipboard-hijacking tools, AnimateClipper and ZigClipper, to intercept cryptocurrency transactions; public reporting does not specify which platform these target.<\/li>\n<\/ul>\n<h3>Payload Overview<\/h3>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 27.2727%; text-align: left;\"><strong>Payload \/ Technique<\/strong><\/th>\n<th style=\"width: 35.2008%; text-align: left;\"><strong>Platform<\/strong><\/th>\n<th style=\"width: 36.4693%; text-align: left;\"><strong>Operational Risk<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 27.2727%;\">MacSync<\/td>\n<td style=\"width: 35.2008%;\">macOS<\/td>\n<td style=\"width: 36.4693%;\">Steals browser credentials, Telegram data, and Apple Notes content<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 27.2727%;\">AMOS malware helper<\/td>\n<td style=\"width: 35.2008%;\">macOS<\/td>\n<td style=\"width: 36.4693%;\">Establishes persistence and enrolls devices for further tasking<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 27.2727%;\">Amatera Stealer<\/td>\n<td style=\"width: 35.2008%;\">Windows<\/td>\n<td style=\"width: 36.4693%;\">Loads in memory, evading disk-based detection<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 27.2727%;\">AMSI bypass + scheduled task creation<\/td>\n<td style=\"width: 35.2008%;\">Windows<\/td>\n<td style=\"width: 36.4693%;\">Attack technique enabling stealthy PowerShell execution during the chain<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 27.2727%;\">AnimateClipper \/ ZigClipper<\/td>\n<td style=\"width: 35.2008%;\">Not specified in public reporting<\/td>\n<td style=\"width: 36.4693%;\">Hijacks clipboard contents to redirect cryptocurrency transfers<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Where Hexnode fits<\/h2>\n<p>ClickFix attacks rely on native operating system tools, which puts the emphasis on endpoint visibility rather than download scanning.<\/p>\n<h3>Detection and containment (XDR):<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> now covers Windows and macOS endpoints, giving admins one console to investigate suspicious PowerShell, mshta, or Terminal activity consistent with ClickFix execution.<\/li>\n<li>When XDR flags a suspicious process chain, admins can isolate or quarantine the affected endpoint directly from the console to limit further spread.<\/li>\n<\/ul>\n<h3>Prevention at the endpoint (UEM):<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> lets admins enforce native Application Restrictions and AppLocker policies to block unauthorized executables from launching, giving IT a way to restrict unwanted software from running.<\/li>\n<\/ul>\n<h3>What Hexnode doesn&#8217;t cover:<\/h3>\n<p>Hexnode does not detect specific malware families like MacSync or Amatera Stealer, patch third-party browsers or wallet apps, or monitor Reddit or ad-platform account activity. Those controls remain with the affected vendors and the organization&#8217;s account-security team.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity framework\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-300x225.png?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-768x576.png?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity framework\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Building a cybersecurity framework for your enterprise\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Explore common cybersecurity framework types and how UEM strengthens organizational defenses against network penetration.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/building-a-cybersecurity-framework-for-your-enterprise\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What is ClickFix and why does it work?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>ClickFix tricks users into pasting a malicious command into Run, PowerShell, or Terminal. Since the user runs it themselves with legitimate tools, it can evade some browser and download defenses.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Was HBO Max&#8217;s own infrastructure breached?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Public reporting does not confirm a breach of HBO Max&#8217;s core systems. Attackers compromised its verified Reddit account. Warner Bros. Discovery had not responded to questions at the time of reporting.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What should security teams check after this campaign?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Review whether employees clicked HBO Max, AI tool, or macOS app ads during the campaign window. Check endpoint logs for PowerShell, mshta, or Terminal activity matching the chains above.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>The HBO Max Reddit account hijack shows how a single compromised social account can distribute infostealer malware to a wide, untargeted audience. ClickFix ads work because they turn the victim into the execution engine, using trusted operating system tools instead of a traditional download.<\/p>\n<p>Enterprises need endpoint visibility across Windows and macOS, script execution controls, and clear governance over brand and advertising accounts. No single control removes this risk entirely, but layered detection and response narrows the window attackers have to operate.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stop attacks before they spread. <\/h5><p>See how Hexnode UEM and XDR secure Windows and macOS endpoints together. <\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Attackers compromised HBO Max&#8217;s verified Reddit account and used it to run malicious advertisements. Hudson&#8230;<\/p>\n","protected":false},"author":5,"featured_media":1716,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,17],"class_list":["post-1688","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-macos","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>HBO Max Reddit Account Hijack Pushes ClickFix Malware<\/title>\n<meta name=\"description\" content=\"The HBO Max Reddit account hijack pushed ClickFix ads that delivered Windows and macOS infostealer malware.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HBO Max Reddit Account Hijack Pushes ClickFix Malware\" \/>\n<meta property=\"og:description\" content=\"The HBO Max Reddit account hijack pushed ClickFix ads that delivered Windows and macOS infostealer malware.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-16T09:23:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-18T04:59:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/hbo-max-reddit-account-hijack.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"HBO Max Reddit Account Hijack: ClickFix Ads Push Windows and macOS Infostealers\",\"datePublished\":\"2026-09-16T09:23:34+00:00\",\"dateModified\":\"2026-09-18T04:59:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\\\/\"},\"wordCount\":1020,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hbo-max-reddit-account-hijack.jpeg?format=webp\",\"articleSection\":[\"Malware\",\"macOS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\\\/\",\"name\":\"HBO Max Reddit Account Hijack Pushes ClickFix Malware\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hbo-max-reddit-account-hijack.jpeg?format=webp\",\"datePublished\":\"2026-09-16T09:23:34+00:00\",\"dateModified\":\"2026-09-18T04:59:28+00:00\",\"description\":\"The HBO Max Reddit account hijack pushed ClickFix ads that delivered Windows and macOS infostealer malware.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hbo-max-reddit-account-hijack.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hbo-max-reddit-account-hijack.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"hbo max reddit account hijack\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"HBO Max Reddit Account Hijack: ClickFix Ads Push Windows and macOS Infostealers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"description\":\"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"HBO Max Reddit Account Hijack Pushes ClickFix Malware","description":"The HBO Max Reddit account hijack pushed ClickFix ads that delivered Windows and macOS infostealer malware.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/","og_locale":"en_US","og_type":"article","og_title":"HBO Max Reddit Account Hijack Pushes ClickFix Malware","og_description":"The HBO Max Reddit account hijack pushed ClickFix ads that delivered Windows and macOS infostealer malware.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-16T09:23:34+00:00","article_modified_time":"2026-09-18T04:59:28+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/hbo-max-reddit-account-hijack.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"HBO Max Reddit Account Hijack: ClickFix Ads Push Windows and macOS Infostealers","datePublished":"2026-09-16T09:23:34+00:00","dateModified":"2026-09-18T04:59:28+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/"},"wordCount":1020,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/hbo-max-reddit-account-hijack.jpeg?format=webp","articleSection":["Malware","macOS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/","url":"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/","name":"HBO Max Reddit Account Hijack Pushes ClickFix Malware","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/hbo-max-reddit-account-hijack.jpeg?format=webp","datePublished":"2026-09-16T09:23:34+00:00","dateModified":"2026-09-18T04:59:28+00:00","description":"The HBO Max Reddit account hijack pushed ClickFix ads that delivered Windows and macOS infostealer malware.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/hbo-max-reddit-account-hijack.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/hbo-max-reddit-account-hijack.jpeg?format=webp","width":1340,"height":700,"caption":"hbo max reddit account hijack"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/hbo-max-reddit-account-hijack-clickfix-ads-push-windows-and-macos-infostealers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"HBO Max Reddit Account Hijack: ClickFix Ads Push Windows and macOS Infostealers"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"description":"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1688","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1688"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1688\/revisions"}],"predecessor-version":[{"id":1722,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1688\/revisions\/1722"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1716"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1688"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1688"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}