Attackers used HBO Max’s compromised verified Reddit account to distribute 108 malicious ads in roughly 48 hours, but the initial access method has not been publicly disclosed. The ads impersonated HBO Max, AI and developer tools, coding software, and macOS utilities, then delivered different information stealing or...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: How did attackers compromise HBO Max’s verified Reddit account in September 2026 to distribute 108 malicious ads over 48 hours as part of th. Article summary: Attackers’ exact method of taking over HBO Max’s verified Reddit account is not publicly known. They used the compromised `u/hbomax` advertising identity—not a demonstrated compromise of HBO Max’s streaming platform—to r. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
A verified brand account can make a malicious ad appear far more credible than an ordinary scam. In September 2026, attackers used the compromised u/hbomax Reddit account to publish 108 malicious advertisements over about 48 hours in a campaign researchers call PasteSwitch. The ads targeted both macOS and Windows users with ClickFix social engineering and information-stealing malware. 3
5
Crucially, public reporting does not establish how the attackers obtained access to HBO Max’s Reddit advertising identity. Nor does it show that HBO Max’s streaming service, Warner Bros. Discovery systems, or other corporate accounts were breached. 3
The attackers took advantage of the account’s verified status to run ads that appeared to originate from HBO Max. Researchers documented five lure groups: 40 ads pointing to hbomaxx[.]app, six to hbomax-macos[.]com, 36 to the fake AI/developer site codex-craft[.]com, 15 to a fake macOS disk-cleaning guide, and 11 to code-desktop[.]com. 3
That distribution shows why the incident mattered beyond a single spoofed streaming-service page. The account was used as a malvertising channel for a broader, cross-platform delivery operation rather than solely to impersonate HBO Max. 3
5
ClickFix campaigns avoid a conventional malware download prompt. Instead, the malicious landing page presents a supposed download, verification, or repair step and tells the visitor to copy and execute a command.
In this case, the fake sites posed as a macOS HBO Max application, AI or developer tools, disk-cleaning software, and coding products. macOS visitors were directed to use Terminal, while Windows users were guided to tools such as the Run dialog or PowerShell. 3
4
The critical deception was social rather than technical: the victim supplied the final authorization by pasting and running the command. That approach can make a malicious action look like an ordinary troubleshooting or installation instruction while using legitimate operating-system utilities. 3
5
A simple rule helps prevent this class of attack: a website should never require someone to paste an unfamiliar command into Terminal, Run, Command Prompt, or PowerShell to install an app, “verify” their device, fix an error, or claim a download.
Researchers reported that macOS chains used commands that fetched and ran scripts, leading to the MacSync malware family. Reported MacSync collection capabilities included browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords. 3
5
The operation also used an AMOS helper component. According to the reported analysis, it created persistence in a directory named to resemble a macOS system component and could register an infected device with attacker-controlled infrastructure for subsequent tasking. 3
5
PasteSwitch also included cryptocurrency-themed lures: counterfeit Ledger, Trezor Suite, and Exodus applications intended to capture wallet recovery phrases. A recovery phrase can provide access to a cryptocurrency wallet, so users should only obtain wallet software from the vendor’s official site or a verified app-store listing. 3
On Windows, reported PasteSwitch activity used mshta and PowerShell-based execution paths. One observed chain used a polyglot file, established a scheduled task, and eventually loaded Amatera Stealer into memory through obfuscated PowerShell and shellcode. 3
5
Researchers reported that Amatera could fingerprint a host, capture screenshots, steal browser credentials, enumerate processes and network information, communicate with attacker infrastructure, and support additional payload delivery. Loading malware in memory can reduce obvious on-disk artifacts, but it does not make the compromise harmless or invisible to endpoint protections. 3
5
The operation was also linked to AnimateClipper and ZigClipper, persistent clipboard hijackers designed to swap a copied cryptocurrency destination address for an attacker-controlled address. If a victim fails to compare the pasted address with the intended recipient’s address, a transfer could be sent to the wrong wallet. 4
5
Researchers further reported that these clippers could retrieve rotating command-and-control information from attacker-controlled Binance Smart Chain smart contracts. Using contract data as a “dead drop” can avoid reliance on one fixed command-and-control hostname. 4
5
For cryptocurrency transfers, compare the complete receiving address—or at minimum several characters at both the beginning and end—on the final confirmation screen, especially after copying and pasting it.
After the ads were reported, a Reddit administrator reportedly paused or suspended them and escalated the matter to Reddit’s Security and Safety teams. 3
4
The most consequential unanswered question is how u/hbomax was compromised. Initial reporting did not identify whether the access came from stolen credentials, a compromised advertising workflow, an insider route, or another method. 3
There is also no public confirmation of how many people executed the commands, what data was stolen, or whether stolen credentials were later used elsewhere. Similarly, the available reporting does not demonstrate access to HBO Max’s streaming platform or broader Warner Bros. Discovery infrastructure. 3
This incident is a reminder that verification badges and recognizable brands reduce neither phishing risk nor the need to validate software sources. Treat unexpected ads for desktop apps—particularly apps that do not normally exist for a platform—as suspicious.
If a command was already run from one of these pages, disconnect the device from networks where practical, contact an IT or incident-response team, change important passwords from a known-clean device, revoke active sessions, and review cryptocurrency accounts and wallet activity. Organizations should also protect advertising and social-media accounts with phishing-resistant multi-factor authentication, least-privilege access, and close monitoring of newly created campaigns.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Attackers used HBO Max’s compromised verified Reddit account to distribute 108 malicious ads in roughly 48 hours, but the initial access method has not been publicly disclosed.
Attackers used HBO Max’s compromised verified Reddit account to distribute 108 malicious ads in roughly 48 hours, but the initial access method has not been publicly disclosed. The ads impersonated HBO Max, AI and developer tools, coding software, and macOS utilities, then delivered different information stealing or cryptocurrency focused payloads depending on the victim’s platform.
Reddit reportedly paused or suspended the ads after they were reported, while no public evidence has established compromise of HBO Max’s streaming platform or other Warner Bros.