Back Theregister HBO Max Reddit account compromised to serve ClickFix attacks
Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware
New hardware device can RAM into encrypted memory, expose your data 4 hours ago
New hardware device can RAM into encrypted memory, expose your data
OpenAI's malicious bot swarm attacked RubyGems 4 hours ago
OpenAI's malicious bot swarm attacked RubyGems
Perfect-10 GitLab bug under attack days after patch lands 8 hours ago
Perfect-10 GitLab bug under attack days after patch lands
UK.gov begins killing off passwords for 23 million users 13 hours ago
UK.gov begins killing off passwords for 23 million users
Security through obscurity is dead, and AI delivered the fatal blow 1 day ago
Security through obscurity is dead, and AI delivered the fatal blow
Someone compromised the official HBO Max account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware.
A user uncovered the infostealer ads on September 6, noting that the ad showed u/hbomax as the author — this is the verified HBO Max account — and advertised a macOS app for HBO Max. The streaming service does not offer a native client for the Mac.
Anyone who clicked on the malicious ad would then be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button.
Clicking the button produced instructions telling the user to copy and paste a command into Terminal on macOS.
The security sleuth described that as “the classic infostealer/clickfix paste this command to download,” noting that they tested all of this in a sandboxed environment, and didn’t actually run the executable on their machine. “My guess is that the account is compromised,” they concluded.
Three days later, paused the infostealer-dropping ads, and an admin said the social media platform’s safety and security teams were investigating what happened.
HBO Max’s parent company Warner Bros. Discovery didn’t immediately respond to The Register ’s inquiries the account takeover - including who hijacked the streaming service’s account and how they did it. Maybe someone who didn’t like the House of the Dragon season 3 finale? We will update this story if and when we hear back.
Researchers at Hudson Rock and ADAMnetworks analyzed the ads, and in a couple of reports said the HBO Max account hijacking was part of a “ massive 48-hour malvertising blitz ” that pushed 108 distinct ads using multiple software lures.
They named the campaign PasteSwitch, and said it serves up targeted malware aimed at victims’ operating system - either macOS or Windows. The payloads include infostealers, malware loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications.
The cryptocurrency clippers - PasteSwitch delivers either AnimateClipper or ZigClipper - also provide blockchain-based command-and-control fallbacks for the attackers. They use Binance Smart Chain (BSC) contracts to dynamically fetch whatever C2 domain the crooks are using at any given time.
“Between March and July 2026, researchers observed 36 mainnet changes executed by the same attacker controller address,” Hudson Rock said. “Because the C2 domain is hosted directly on the blockchain, the infrastructure demonstrates dynamic resilience, allowing the threat actors to easily rotate burned domains.”
In addition to HBO Max, the attackers used developer-tool, disk-cleaner, and AI-themed lures, including fake OpenAI Codex ads, which crims have previously used to push Mac malware .
Of the 108 ads, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com).
“The campaign proves once again why trusted distribution channels are becoming prime targets for infostealer delivery,” Hudson Rock co-founder and CTO Alon Gal said in a post.
It also shows that miscreants continue to make heavy use of ClickFix attacks , so there’s little sign this social engineering method is going away anytime soon.®
HBO Max account compromised to serve ClickFix attacks
Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware
Oracle celebrates banner quarter with another round of layoffs
Congratulations on helping Larry Ellison's AI cloud boom. Now please pack your bags and go
HPE makes its “unified storage” claim real as B10000 R6 hits GA
PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity
New hardware device can RAM into encrypted memory, expose your data
Attackers would need physical access to the server to pull off the DDR5 trick
Europe's right-to-repair rules are broken, not beaten
Patchy compliance is an argument for stronger enforcement, not abandoning the project
OpenAI's malicious bot swarm attacked RubyGems
Ruby are you ok? Ruby are you ok? Are you ok Ruby?
PERSONAL TECH Smartphone makers don't bother to comply with EU repairability requirements
Smartphone makers don't bother to comply with EU repairability requirements
NETWORKS Virgin Media offloads email services to third-party provider
Virgin Media offloads email services to third-party provider
offbeat Retired man turns spare room into Soviet-era supercomputer
Retired man turns spare room into Soviet-era supercomputer
CYBER-CRIME Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
software Another Microsoft team admits it’s struggling to handle flood of AI-generated code
Another Microsoft team admits it’s struggling to handle flood of AI-generated code
virtualization VMware defends ending downloads of SDK that helps VM backups – or migrations to rivals
VMware defends ending downloads of SDK that helps VM backups – or migrations to rivals
on-prem Datacenter developers want your backyard. FAS says negotiate harder Tax breaks, water, noise, decommissioning - report tells local officials what to nail down before signing
Datacenter developers want your backyard. FAS says negotiate harder
Tax breaks, water, noise, decommissioning - report tells local officials what to nail down before signing
LEGAL Nvidia's Groq acquihire is on the DOJ's radar, but it's already too late Even if regulators did somehow unwind the $20B deal, there's a growing list of alternatives ready to take Groq's place, no merger required
Nvidia's Groq acquihire is on the DOJ's radar, but it's already too late
Even if regulators did somehow unwind the $20B deal, there's a growing list of alternatives ready to take Groq's place, no merger required
SECURITY Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent War is peace. Freedom is slavery. Privacy is surveillance
Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent
War is peace. Freedom is slavery. Privacy is surveillance
SYSTEMS d-Matrix drinks the Nvidia Kool-Aid with NVLink Fusion and MGX rack designs AI infrastructure startup joins Qualcomm, Arm, Marvell, Amazon, Fujitsu, and MediaTek as NVLink true believers
d-Matrix drinks the Nvidia Kool-Aid with NVLink Fusion and MGX rack designs
AI infrastructure startup joins Qualcomm, Arm, Marvell, Amazon, Fujitsu, and MediaTek as NVLink true believers
ai and ml Anthropic reveals fourth likely crime committed by its AI Claude's Felony Bench rap sheet is now as long as OpenAI's
Anthropic reveals fourth likely crime committed by its AI
Claude's Felony Bench rap sheet is now as long as OpenAI's
Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
EQT buys majority in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
On the plus side, infosec's a good bet for a long, stable career
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line
Acquisition gives open source CSS framework 'a stable long-term '
Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push
Switzerland tests a FOSS escape route from Microsoft 365
Swiss Army sticks a knife in American cloud apps with its own FOSS push
Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin
Feel peak Windows was 7? You might like Kumander Linux
Debian and Xfce – solid, sensible choices – with a pretty skin
Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted
Canonical shuttering some of its legacy chat channels
The Ubuntu Pastebin went in June, IRC gets demoted
Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Audacity audio-editing app no longer looks like it's from the early 2000s
The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast A real alternative to running some kind of FOSS Unix clone
Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast
A real alternative to running some kind of FOSS Unix clone
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
