HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware

Attackers reportedly hijacked HBO Max’s verified Reddit account to run 108 malicious ads delivering ClickFix malware to Windows and Mac users.

Sep 16, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A verified HBO Max account looked like a safe place to encounter an ad. Attackers reportedly turned that credibility into a malware delivery system.

Researchers at Hudson Rock found that attackers compromised HBO Max’s verified Reddit advertising account and used it to run 108 malicious ads over roughly 48 hours. The ads sent users to attacker-controlled sites employing ClickFix techniques to trick victims into executing commands that installed malware on Windows and macOS devices.

The campaign shows how ClickFix is evolving beyond a single fake error message or download lure. By combining a trusted brand account with fake streaming, AI, developer, and macOS utility sites, the attackers could target different users with different malware while relying on victims to perform the crucial execution step themselves.

Attackers pushed 108 malicious ads in roughly 48 hours

Earlier this week, we covered how attackers abused a compromised Brevo account connected to Trezor to send a malicious email to the company’s newsletter subscribers. This time, attackers went after a different trusted channel: they compromised HBO Max’s legitimate, verified Reddit account and used its advertising privileges to distribute malware-laced ads.

According to SecurityWeek, the attackers ran the campaign for roughly 48 hours and published 108 malicious ads through the compromised Reddit account u/hbomax.

Per HudsonRock, the ads were not limited to HBO Max, either:

  • 40 promoted hbomaxx[.]app
  • 36 promoted a fake AI/developer site called codex-craft[.]com
  • 15 promoted a fake macOS system utility called apple.clean-disk-guide[.]com
  • 11 pointed to code-desktop[.]com
  • Six promoted another fake HBO Max macOS site called hbomax-macos[.]com

That variety appears deliberate. Instead of relying only on HBO Max fans, the attackers used the account to reach people looking for streaming services, AI and developer tools, and macOS utilities, giving the same malware-delivery operation several different lures.

Upon clicking the malicious ads, victims were directed to convincing websites that used ClickFix to push them through the final stage of the attack.

Researchers observed several payloads including MacSync, AMOS Helper, bogus wallet applications, and several infostealers. Windows users were handled differently and directed toward MSHTA and PowerShell execution, which launched the Amatera Stealer on their devices.

Advertisement

What makes ClickFix attacks so dangerous

ClickFix is a social engineering technique that tricks users into copying and running an attacker-provided command on their own computers.

That makes the attack particularly dangerous because the victim is effectively performing the execution step for the attacker. What makes it more concerning is that the victims often run these instructions with the same level of permission they hold and, in some cases, may intentionally bypass security tools that try to flag or block the attack.

There is another problem: the instructions can look more trustworthy than the malware itself.

A victim may refuse to download an unfamiliar .exe or .dmg file, but may follow a page telling them to “verify” their browser, “install” an application, or “fix” an error by pasting a command. Once that command runs, the attack moves from the browser into the operating system, where it can retrieve and execute the actual payload.

How, then, can you stay safe?

If you clicked the ad and ran the command

If you clicked one of the malicious HBO Max ads and followed the instructions to paste or run a command, assume the device may be compromised. From a clean device, change passwords for important accounts and enable multifactor authentication where available.

The malware observed in this campaign can target credentials, browser data, and cryptocurrency information, so check your accounts for any unfamiliar logins, password reset requests, or transactions.

If you used cryptocurrency wallets on the device, treat their credentials and recovery phrases as potentially exposed, and consider having a qualified security professional examine the device.

Advertisement

If you haven’t run the command

For those who saw the ad but didn’t follow the instructions, and for everyone else, the situation is different. Because ClickFix is difficult to distinguish from normal technical help, the safer approach is to verify the instruction before running it:

  • Check the command against another reputable source. Search for the exact command or the specific task you are trying to complete and see whether independent sources recommend the same step.
  • Understand what an instruction does. Be particularly cautious with commands that download and immediately execute code, such as those using curl, wget, PowerShell, or similar tools. If you are unsure, you shouldn’t proceed.
  • Get software from the developer’s official website or a trusted app store, not from installation commands in an advertisement or on an unfamiliar webpage.

Security software can help block known malicious domains, scripts, and payloads, but ClickFix attacks exploit something technology cannot completely filter: a user’s willingness to follow convincing instructions. Treat any webpage or advertisement that asks you to paste commands into Terminal, PowerShell, or another system tool as a warning sign, even if the site or account appears legitimate.

Also read: Attackers are increasingly turning trusted platforms into attack infrastructure. See how a Bing Ads campaign abused Microsoft Azure to redirect users to fraudulent tech support pages.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.