Techcrunch HBO Max Account Compromise Fuels ClickFix Malware Campaign
Article Content
- •108 malicious ads were published via a compromised HBO Max account in 48 hours.
- •The ClickFix technique tricks users into executing malicious commands in their terminal.
- •The PasteSwitch operation targets both macOS and Windows systems with various malware types.
In September 2026, a compromised HBO Max account was used to publish 108 malicious ads over 48 hours, targeting both macOS and Windows users. The ads employed a ClickFix technique, tricking users into pasting malicious commands into their system terminals, leading to the installation of information-stealing malware. This operation, dubbed PasteSwitch, spans various malware types including MacSync stealers and AMOS malware. The attackers utilized deceptive TLS and contract-controlled cryptocurrency clippers as part of their infrastructure. The campaign's scale and sophistication have prompted security investigations, with affected users advised to check for malware. The attack highlights the growing prevalence of ClickFix tactics in cybercrime. Administrators have paused the malicious ads and initiated security reviews.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track Mentalpositive, ClickFix and HBO Max in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Russia's AI-Driven Cyber Espionage Targets Ukraine and Europe A Russian-linked hacking group, identified as GTG-20006, has utilized Anthropic's Claude AI to automate cyber espionage against over 20 organizations, primarily in Ukraine and Europe. The group targeted Ukrainian government officials, military personnel, and drone manufacturers through sophisticated phishing and…
Rapid7 Reports Surge in Vulnerability Exploitation Outpacing Patching Efforts Rapid7's Q2 2026 Threat Landscape Report reveals a significant increase in vulnerability disclosures, with high and critical vulnerabilities doubling to 8,539. Newly exploited vulnerabilities surged by 40%, with 62% requiring no user interaction to exploit. The report highlights that attackers are leveraging…