Skip to content
HBO Max Reddit account hijacked for ClickFix malware campaign

HBO Max Reddit account hijacked for ClickFix malware campaign

Techobserver.In September 14, 2026

ClickFix attacks targeted both Windows and macOS users with information-stealing malware

Campaign distributed fake cryptocurrency wallet applications to steal recovery phrases

The ClickFix technique has gained popularity among cybercriminals because victims execute the malicious commands themselves using built-in operating system tools, potentially bypassing browser security measures and antivirus software designed to detect conventional malware downloads.

Hudson Rock and ADAMnetworks have linked the attack to a larger operation they call PasteSwitch, which targets both Windows and macOS systems. The campaign has been used to distribute information stealers, loaders, cryptocurrency clippers and fake cryptocurrency wallet applications.

The researchers said PasteSwitch refers to the operation’s use of attacker-supplied commands that victims paste into their systems. The attackers’ backend infrastructure switches between campaigns, platforms, payloads and cryptocurrency theft methods depending on who visits the malicious sites.

One of the fake HBO Max websites used in the campaign was hbomaxx[.]us. Clicking the download button did not download an application but instead displayed instructions telling visitors to open Terminal, the command line interface on macOS, and paste a command. The command used Base64 encoding, a method of obscuring text that converts readable characters into a different format, to hide what it actually executed.

One malware family used in this attack is MacSync, which Hudson Rock said steals browser credentials, Firefox browser profiles, Telegram messaging data, Apple Notes and macOS system passwords. Another attack chain deployed a malware component that establishes persistence using a hidden directory on the infected system. The malware can then connect to attacker-controlled servers to receive additional instructions.

The campaign has also distributed fake Ledger, Trezor Suite and Exodus cryptocurrency wallet applications designed to steal victims’ wallet recovery phrases, the series of words that provide complete access to cryptocurrency holdings.

On Windows systems, the PasteSwitch operation has been observed displaying instructions that cause victims to execute commands using mshta and PowerShell, built-in Windows utilities. Hudson Rock said one Windows attack chain used a file that appeared to be an MP3 audio file but contained hidden instructions. This created a scheduled task, launched PowerShell, disabled Microsoft ‘s Antimalware Scan Interface (AMSI), a Windows security feature that scans scripts for malicious content, and generated victim-specific infrastructure based on the computer name and username.

Later stages used obfuscated PowerShell commands and shellcode, low-level computer instructions, to load the Amatera Stealer malware directly into the computer’s memory without first saving it to the hard drive, making it harder for security software to detect.

The PasteSwitch operation has also distributed cryptocurrency clipboard hijacking malware , including variants called AnimateClipper and ZigClipper. These monitor the clipboard and replace cryptocurrency wallet addresses copied by users with addresses controlled by the attackers, redirecting cryptocurrency transfers.

Your Questions, Answered

ClickFix is a social engineering technique where attackers trick users into copying and pasting malicious commands into their operating system's command line while believing they are fixing an error or installing software. Victims execute the malware themselves using legitimate system tools.

The campaign distributed MacSync information stealer, Amatera Stealer, cryptocurrency clippers like AnimateClipper and ZigClipper, and fake cryptocurrency wallet applications designed to steal recovery phrases.

Users should never copy and paste commands from websites into Terminal or PowerShell. Legitimate software never requires manual command line installation. Always download applications from official app stores or verified developer websites.