Skip to content
HBO Max Reddit account compromised to serve ClickFix attacks

HBO Max Reddit account compromised to serve ClickFix attacks

Theregister September 14, 2026

Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware

New hardware device can RAM into encrypted memory, expose your data 4 hours ago

New hardware device can RAM into encrypted memory, expose your data

OpenAI's malicious bot swarm attacked RubyGems 4 hours ago

OpenAI's malicious bot swarm attacked RubyGems

Perfect-10 GitLab bug under attack days after patch lands 8 hours ago

Perfect-10 GitLab bug under attack days after patch lands

UK.gov begins killing off passwords for 23 million users 13 hours ago

UK.gov begins killing off passwords for 23 million users

Security through obscurity is dead, and AI delivered the fatal blow 1 day ago

Security through obscurity is dead, and AI delivered the fatal blow

Someone compromised the official HBO Max account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware.

A user uncovered the infostealer ads on September 6, noting that the ad showed u/hbomax as the author — this is the verified HBO Max account — and advertised a macOS app for HBO Max. The streaming service does not offer a native client for the Mac.

Anyone who clicked on the malicious ad would then be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button.

Clicking the button produced instructions telling the user to copy and paste a command into Terminal on macOS.

The security sleuth described that as “the classic infostealer/clickfix paste this command to download,” noting that they tested all of this in a sandboxed environment, and didn’t actually run the executable on their machine. “My guess is that the account is compromised,” they concluded.

Three days later, paused the infostealer-dropping ads, and an admin said the social media platform’s safety and security teams were investigating what happened.

HBO Max’s parent company Warner Bros. Discovery didn’t immediately respond to The Register ’s inquiries the account takeover - including who hijacked the streaming service’s account and how they did it. Maybe someone who didn’t like the House of the Dragon season 3 finale? We will update this story if and when we hear back.

Researchers at Hudson Rock and ADAMnetworks analyzed the ads, and in a couple of reports said the HBO Max account hijacking was part of a “ massive 48-hour malvertising blitz ” that pushed 108 distinct ads using multiple software lures.

They named the campaign PasteSwitch, and said it serves up targeted malware aimed at victims’ operating system - either macOS or Windows. The payloads include infostealers, malware loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications.

The cryptocurrency clippers - PasteSwitch delivers either AnimateClipper or ZigClipper - also provide blockchain-based command-and-control fallbacks for the attackers. They use Binance Smart Chain (BSC) contracts to dynamically fetch whatever C2 domain the crooks are using at any given time.

“Between March and July 2026, researchers observed 36 mainnet changes executed by the same attacker controller address,” Hudson Rock said. “Because the C2 domain is hosted directly on the blockchain, the infrastructure demonstrates dynamic resilience, allowing the threat actors to easily rotate burned domains.”

In addition to HBO Max, the attackers used developer-tool, disk-cleaner, and AI-themed lures, including fake OpenAI Codex ads, which crims have previously used to push Mac malware .

Of the 108 ads, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com).

“The campaign proves once again why trusted distribution channels are becoming prime targets for infostealer delivery,” Hudson Rock co-founder and CTO Alon Gal said in a post.

It also shows that miscreants continue to make heavy use of ClickFix attacks , so there’s little sign this social engineering method is going away anytime soon.®

HBO Max account compromised to serve ClickFix attacks

Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware

Oracle celebrates banner quarter with another round of layoffs

Congratulations on helping Larry Ellison's AI cloud boom. Now please pack your bags and go

HPE makes its “unified storage” claim real as B10000 R6 hits GA

PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity

New hardware device can RAM into encrypted memory, expose your data

Attackers would need physical access to the server to pull off the DDR5 trick

Europe's right-to-repair rules are broken, not beaten

Patchy compliance is an argument for stronger enforcement, not abandoning the project

OpenAI's malicious bot swarm attacked RubyGems

Ruby are you ok? Ruby are you ok? Are you ok Ruby?

PERSONAL TECH Smartphone makers don't bother to comply with EU repairability requirements

Smartphone makers don't bother to comply with EU repairability requirements

NETWORKS Virgin Media offloads email services to third-party provider

Virgin Media offloads email services to third-party provider

offbeat Retired man turns spare room into Soviet-era supercomputer

Retired man turns spare room into Soviet-era supercomputer

CYBER-CRIME Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

software Another Microsoft team admits it’s struggling to handle flood of AI-generated code

Another Microsoft team admits it’s struggling to handle flood of AI-generated code

virtualization VMware defends ending downloads of SDK that helps VM backups – or migrations to rivals

VMware defends ending downloads of SDK that helps VM backups – or migrations to rivals

on-prem Datacenter developers want your backyard. FAS says negotiate harder Tax breaks, water, noise, decommissioning - report tells local officials what to nail down before signing

Datacenter developers want your backyard. FAS says negotiate harder

Tax breaks, water, noise, decommissioning - report tells local officials what to nail down before signing

LEGAL Nvidia's Groq acquihire is on the DOJ's radar, but it's already too late Even if regulators did somehow unwind the $20B deal, there's a growing list of alternatives ready to take Groq's place, no merger required

Nvidia's Groq acquihire is on the DOJ's radar, but it's already too late

Even if regulators did somehow unwind the $20B deal, there's a growing list of alternatives ready to take Groq's place, no merger required

SECURITY Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent War is peace. Freedom is slavery. Privacy is surveillance

Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent

War is peace. Freedom is slavery. Privacy is surveillance

SYSTEMS d-Matrix drinks the Nvidia Kool-Aid with NVLink Fusion and MGX rack designs AI infrastructure startup joins Qualcomm, Arm, Marvell, Amazon, Fujitsu, and MediaTek as NVLink true believers

d-Matrix drinks the Nvidia Kool-Aid with NVLink Fusion and MGX rack designs

AI infrastructure startup joins Qualcomm, Arm, Marvell, Amazon, Fujitsu, and MediaTek as NVLink true believers

ai and ml Anthropic reveals fourth likely crime committed by its AI Claude's Felony Bench rap sheet is now as long as OpenAI's

Anthropic reveals fourth likely crime committed by its AI

Claude's Felony Bench rap sheet is now as long as OpenAI's

Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Russians are posing as Signal support to launch phishing attacks

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Black Hat and DEF CON

DEF CON Franklin project enlists hackers to harden critical infrastructure

Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

EQT buys majority in Swiss cybersecurity biz Acronis

Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

On the plus side, infosec's a good bet for a long, stable career

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line

Acquisition gives open source CSS framework 'a stable long-term '

Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push

Switzerland tests a FOSS escape route from Microsoft 365

Swiss Army sticks a knife in American cloud apps with its own FOSS push

Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin

Feel peak Windows was 7? You might like Kumander Linux

Debian and Xfce – solid, sensible choices – with a pretty skin

Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted

Canonical shuttering some of its legacy chat channels

The Ubuntu Pastebin went in June, IRC gets demoted

Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Audacity audio-editing app no longer looks like it's from the early 2000s

The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast A real alternative to running some kind of FOSS Unix clone

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast

A real alternative to running some kind of FOSS Unix clone