Skip to content
HBO Max Account Compromise Fuels ClickFix Malware Campaign

HBO Max Account Compromise Fuels ClickFix Malware Campaign

First seen 14 Sep 2026, 18:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 19:54 UTC
  • 108 malicious ads were published via a compromised HBO Max account in 48 hours.
  • The ClickFix technique tricks users into executing malicious commands in their terminal.
  • The PasteSwitch operation targets both macOS and Windows systems with various malware types.

In September 2026, a compromised HBO Max account was used to publish 108 malicious ads over 48 hours, targeting both macOS and Windows users. The ads employed a ClickFix technique, tricking users into pasting malicious commands into their system terminals, leading to the installation of information-stealing malware. This operation, dubbed PasteSwitch, spans various malware types including MacSync stealers and AMOS malware. The attackers utilized deceptive TLS and contract-controlled cryptocurrency clippers as part of their infrastructure. The campaign's scale and sophistication have prompted security investigations, with affected users advised to check for malware. The attack highlights the growing prevalence of ClickFix tactics in cybercrime. Administrators have paused the malicious ads and initiated security reviews.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-12
HBO Max account compromised
Attackers used the account to publish 108 malicious ads targeting users over 48 hours.
adamnet.works
2026-09-14
Security investigations initiated
Administrators paused the ads and began investigating the security breach.
adamnet.works
2026-09-14
PasteSwitch operation detailed
Hudson Rock and ADAMnetworks confirmed the PasteSwitch operation's scope and methods.
Infostealers

More articles in this cluster (7)

Following this threat?

Track Mentalpositive, ClickFix and HBO Max in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed