HBO Max’s hijacked Reddit account ran 108 malicious ads over roughly 48 hours.
Malwarebytes linked the ads to PasteSwitch, an operation targeting Windows and Mac users with information-stealing malware.
Reddit paused the ads and opened an investigation; victim counts and cryptocurrency losses remain unconfirmed.
Hackers hijacked streaming service HBO Max’s verified Reddit account earlier this month and used it to run 108 malicious advertisements over two days, cybersecurity experts warn.
In its report on Monday, researchers from cybercrime intelligence firm Hudson Rock link the account takeover to a broader operation targeting passwords and cryptocurrency wallet information.
Myriad: Who will be the top Spotify artist of 2026? Click to make your prediction.
“The incident was brought to light by Alex Cutts in the r/cybersecurity subreddit. While browsing the platform, they encountered an official Reddit advertisement authored by the verified u/hbomax account,” Hudson Rock wrote. “The ad aggressively promoted a native macOS application for HBO Max, a standalone application that does not currently exist.”
Instead of providing an installer, the site instructed visitors to open Terminal on a Mac, or Run or PowerShell on Windows, and paste a command that could infect their computer.
The technique, known as ClickFix, disguises malicious commands as routine steps for installing software, fixing errors, or proving a visitor is human. The hijacked account gave those instructions the apparent backing of a recognizable company.
Researchers dubbed the operation “PasteSwitch,” warning that its delivery system appears to adapt to the visitor’s device and the software being advertised.
Observed Mac payloads included MacSync and Atomic macOS (AMOS), information-stealer malware designed to steal sensitive information. Reported targets included browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases.
“These clippers utilized Binance Smart Chain (BSC) contracts as mutable C2 dead drops,” researchers wrote, explaining that the malware checks Binance Smart Chain contracts for the latest address of the hackers’ control server. Hackers can then update that address when they switch servers, allowing the malware to keep finding them.
The broader operation was also linked to cryptocurrency clipboard hijackers, which replace a copied wallet address with one controlled by an attacker. A victim who pastes the substituted address without checking it could send funds to the wrong recipient. Stolen recovery phrases pose a separate risk because they can give attackers control of the associated wallet.
According to cybersecurity firm Malwarebytes, Reddit administrators paused the advertisements and opened a security investigation after receiving reports. The report did not establish how the account was compromised or how many people were infected. It described a Reddit account takeover, with no evidence presented of a breach of HBO Max’s streaming service.
ClickFix has appeared in other recent campaigns targeting cryptocurrency users. In August, researchers identified nearly 2,000 compromised WordPress websites supporting a malware operation that used fake verification prompts and could steal wallet information.
Microsoft researchers also described a separate campaign using fake CAPTCHAs to trick Windows users into running malicious commands, with instructions retrieved through BNB Chain.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.
We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.
Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.
Your permission applies to the following domains:
https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.