Attackers used HBO Max’s verified Reddit account to run 108 malicious ads over roughly 48 hours, directing users to ClickFix pages that asked them to paste commands into macOS Terminal or Windows Run. The researchers’ PasteSwitch label describes a cross platform delivery operation that paired brand impersonation wit...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: How did hackers compromise HBO Max’s verified Reddit account to publish 108 malicious ads over 48 hours, how did the ClickFix social-enginee. Article summary: The verified `u/hbomax` Reddit account appears to have been taken over and used as a trusted advertising channel, not as evidence of a confirmed intrusion into HBO Max or Warner Bros. Discovery infrastructure. Researcher. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
A trusted account can make a malicious ad look routine. In this case, researchers said attackers hijacked the verified u/hbomax Reddit account and used it to distribute ClickFix ads that led Windows and macOS visitors toward information-stealing malware. The incident appears to be an abuse of the account and its advertising access—not proof of a breach of HBO Max or Warner Bros. Discovery infrastructure. 19
21
Over about 48 hours, the compromised account ran 108 malicious advertisements, according to researchers cited in reporting on the incident. The ads impersonated HBO Max as well as AI/developer tools and macOS utilities, and researchers linked the activity to a broader operation they called PasteSwitch. 19
21
The campaign was surfaced by Reddit users and investigated by Hudson Rock and ADAMnetworks, with other researchers contributing analysis. Reddit said it had temporarily halted the affected advertisements and was investigating with its Security and Safety teams. 21
29
ClickFix does not need a browser exploit. Instead, it persuades the target to execute a command themselves:
This approach is effective because it combines familiar brands, apparently verified advertising, and a mundane troubleshooting task. The malicious action is authorized by the user, rather than arriving as an obvious executable download or exploiting a software vulnerability. 1
14
Researchers described PasteSwitch as a flexible, cross-platform delivery operation rather than a single static malware campaign. Its landing pages and commands could select different content based on operating system and change destinations or payloads over time. 18
21
27
The macOS branch was reported to deliver MacSync and AMOS Helper-related stealer components. ClickFix campaigns using fake macOS utilities and Terminal instructions have also been documented by Microsoft, illustrating how a pasted command can launch an obfuscated loader on a Mac. 18
11
Researchers associated with the HBO Max incident also reported wallet-themed lures impersonating Ledger, Trezor, and Exodus. The operation included cryptocurrency clipboard-hijacking behavior: malware can watch for a copied wallet address and replace it with an attacker-controlled address before a transfer is made. 21
27
The Windows delivery chain reportedly used a polyglot file presented as an MP3 but capable of acting as an HTA loader, ultimately leading to Amatera Stealer. Amatera—also called ACR or AcridRain Stealer—is a Windows credential and information stealer that has appeared in ClickFix, fake-verification, malvertising, and multi-stage loader campaigns. 18
24
For either operating system, the potential consequence is broader than a single password: infostealers can target browser credentials, active sessions, stored data, and cryptocurrency-wallet information. 4
18
Researchers tied PasteSwitch to infrastructure that used BNB Smart Chain smart contracts as dead-drop-style routing. The reported operation rotated through 36 domains between March and July 2026. 21
This resembles a wider ClickFix pattern in which compromised sites retrieve instructions or payload-routing data from BNB Smart Chain contracts. Because operators can alter on-chain instructions without changing every compromised site, defenders cannot rely solely on blocking one URL or file hash. 3
36
39
The central unanswered question is how attackers gained control of the HBO Max Reddit account or its advertising access. Public reporting has not established whether the cause was stolen credentials, a stolen session token, weak or bypassed multifactor authentication, third-party access, or another route. 19
21
There is also no reliable public accounting of ad impressions, clicks, command execution, infections, financial losses, or affected users. Seeing an ad was not enough to become infected; the victim still had to follow the page’s instructions and run the command. Nor is there public evidence that the incident reached Warner Bros. Discovery corporate, customer, production, or streaming systems. 19
21
ClickFix has become a widely used social-engineering technique across both Windows and macOS. Microsoft has warned that campaigns exploit people’s instinct to resolve minor technical problems, including fake CAPTCHA and verification prompts; separate reporting identified more than 5,400 compromised websites serving ClickFix lures with blockchain-based payload infrastructure. 14
3
The durable takeaway is not to trust a command simply because it appears after an ad, on a familiar-looking website, or behind a verification prompt. Stop if any page asks you to paste text into Terminal, Run, PowerShell, or Windows Terminal. Close the page and obtain software or support instructions directly from the vendor’s official site. 2
14
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Attackers used HBO Max’s verified Reddit account to run 108 malicious ads over roughly 48 hours, directing users to ClickFix pages that asked them to paste commands into macOS Terminal or Windows Run.
Attackers used HBO Max’s verified Reddit account to run 108 malicious ads over roughly 48 hours, directing users to ClickFix pages that asked them to paste commands into macOS Terminal or Windows Run. The researchers’ PasteSwitch label describes a cross platform delivery operation that paired brand impersonation with OS specific infostealers and changeable, blockchain backed routing.
The practical defense is simple: a legitimate CAPTCHA, streaming page, or software support page should never require a visitor to paste a command into Terminal, PowerShell, Windows Terminal, or the Run dialog.