Over a two-day period, hackers seized control of HBO Max’s verified Reddit account and posted 108 malicious advertisements. Security experts caution that these ads were designed to trick visitors into installing malware capable of stealing passwords and cryptocurrency wallet data.
Alex Cutts first flagged the takeover in the r/cybersecurity subreddit. He pointed to an official-looking Reddit advertisement from the verified u/hbomax account that pushed a native macOS app for HBO Max. That app is a fake.
The Malicious Command
Rather than offering an installer, the ad pointed visitors toward Terminal on a Mac or Run or PowerShell on Windows. It directed them to copy and paste a single command into those tools, a command capable of infecting their machine.
The method goes by the name ClickFix, which conceals harmful commands within what look like ordinary steps for putting software in place, correcting faults, or showing a visitor is not a machine. The account that was taken over gave those directions the weight of a familiar brand behind them.
Researchers from cybercrime intelligence firm Hudson Rock dubbed the operation “PasteSwitch.” They found that the delivery system appears to adapt to the visitor’s device and the software being advertised.
What the Malware Steals
On Apple computers, two observed payloads were found: MacSync and Atomic macOS (AMOS). Both are built to steal data from a system, taking hold of sensitive information.
The reported targets were extensive:
- Browser credentials
- Telegram data
- Apple Notes
- Saved passwords
- Cryptocurrency wallet recovery phrases
The attackers employed Binance Smart Chain (BSC) contracts as mutable command-and-control dead drops. The malware looks up the current address of the hackers’ control server by checking these BSC contracts. When the hackers move to a new server, they can change that address, which allows the malware to continue locating it.
The wider operation was connected to clipboard hijackers tied to cryptocurrency. These tools swap a copied wallet address with one run by an attacker. A person who pastes the altered address without inspecting it might send funds to the wrong party.
Recovery phrases that get taken by others create their own danger, since they hand over full command of the wallet to whoever takes them.
The Response So Far
Malwarebytes said Reddit’s administrators stopped the advertisements and launched a security investigation following reports. The report failed to determine how the account was taken over or how many people were affected.
No proof of a breach into HBO Max’s streaming service was offered alongside the account takeover described on Reddit.
Related Campaigns
Other recent campaigns have targeted cryptocurrency users with ClickFix appearing among them. In August, researchers found nearly 2,000 compromised WordPress websites backing a malware operation that relied on fake verification prompts and was capable of stealing wallet information.
Researchers from Microsoft detailed a distinct campaign that used fake CAPTCHAs to fool Windows users into executing malicious commands, with instructions fetched via BNB Chain.
What Victims Should Check
Following the instructions in one of these ads could leave you exposed before you know it. The malware is built to take recovery phrases, which gives an attacker full command over your wallet.
It’s straightforward guidance: review your accounts. Search for any charges you didn’t authorize. Update your recovery phrases should you believe they’ve been compromised.
No victim count or confirmed cryptocurrency losses appear in the report, which serves as a reminder that many of these attacks go unreported. People often see the warning too late.
That a verified corporate account was taken over for spreading this malware is disturbing. It is the sort of attack that makes people doubt whether any online warning can be trusted.
Reddit moved fast to stop the ads, which is encouraging. Unfortunately, they ran for two full days before that happened.
The operation was sophisticated, adjusting itself to the visitor’s device and the software being advertised. It made use of Binance Smart Chain contracts as a dead drop, targeting users running both Mac and Windows systems.
This demonstrates the durability of these campaigns. Researchers discovered thousands of WordPress sites that had been compromised just a few weeks ago, and they were still carrying out the exact same activity.
The key point here is straightforward: always avoid copying commands from sources you don’t know, even when those sources appear to be official.
Questions about how HBO Max’s account was taken over remain unanswered, according to the report, with no public disclosure of the answers yet made.
For now, the best anyone can do is stay alert.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

