Skip to content
Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack

Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack

Securityweek • September 15, 2026

Hackers compromised the official HBO Max account on and used it in a malvertising campaign leading to a ClickFix landing page.

Using the verified u/hbomax account, the threat actors targeted both macOS and Windows users and aggressively a native macOS application for HBO Max, which does not exist.

Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also contained a download button.

“The download button opened a ClickFix prompt that told the visitor to copy a command, open Terminal, paste the command, and run it. This transferred execution from the browser to a trusted system utility under the victim’s control,” ADAMnetworks explains.

On macOS, the attack relied on curl | zsh commands to deliver malware such as MacSync , AMOS Helper, fake wallet applications, and other malicious code to steal users’ information, including their credentials, messages, browser information, and cryptocurrency wallet information, and gain persistent access to their machines.

On Windows, the attack relied on MSHTA and PowerShell to deliver the Amatera Stealer and achieve persistence. Configured for manual credential validation, the malware would bypass network telemetry by spoofing connections to hide its command-and-control (C&C) communication.

The PasteSwitch campaign also used AnimateClipper and ZigClipper as persistent clipboard replacement tools to swap cryptocurrency addresses when users attempted to make a transaction, HudsonRock notes.

According to the security firms, the clipboard stealers use a C&C hosted on the blockchain. The infrastructure was likely set up over a year ago and has been used in attacks since early 2026.

was notified of the malicious activity associated with the official HBO Max account and immediately suspended the ads.

SecurityWeek has emailed Warner Bros., which owns HBO Max, for a statement on the hack and will update this article if the company responds.

Related: Personal, Financial Info Exposed in Revolut Data Breach

Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Related: Telus Warns Customers of Account Breaches

Related: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

Ionut Arghire is an international correspondent for SecurityWeek.

More from Ionut Arghire

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

GitLab Vulnerability Exploited One Day After Disclosure

Check Point Patches Critical VPN Vulnerabilities

Surfshark Systems Targeted by Hackers

PaperCut Flaws Exploited in AI-Powered Attacks

OpenAI Investigates Report Linking AI Agents to RubyGems Attack

240,000 Hit by Data Breach at Japan’s Digital Agency

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases

Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development

New Warnings the Risks of AI to Humanity Revive a Long-Running Debate

Personal, Financial Info Exposed in Revolut Data Breach

Flipboard Whatsapp Whatsapp Email