Cybercriminals hijacked HBO Max's verified Reddit account to distribute 108 distinct malicious advertisements over approximately 48 hours, according to researchers at Hudson Rock. The ads promoted fake versions of HBO Max downloads, AI tools, and Mac utilities, leveraging the credibility of the verified corporate identity to lower user suspicion. This campaign is part of a broader operation dubbed PasteSwitch, which uses a technique called ClickFix to trick users into executing attacker-supplied code themselves.
The attack began when a Reddit user noticed an advertisement from the verified u/hbomax account promoting a native macOS application for HBO Max. Since HBO Max does not offer a native Mac app, the user investigated the link. The landing page appeared legitimate, but clicking the download button triggered a prompt instructing visitors to copy and paste a command into Terminal. This manual execution step is central to ClickFix, a method that bypasses some browser download protections by having the victim run the malicious code directly.
Hudson Rock and researchers from ADAMnetworks identified multiple payload paths within the PasteSwitch operation. On Mac systems, the malware could steal browser credentials, Telegram data, Apple Notes, and macOS passwords. It also included fake cryptocurrency wallet apps for Ledger, Trezor Suite, and Exodus, designed to capture 12- and 24-word recovery phrases. For Windows users, the operation used PowerShell and other tools to load malware into memory, potentially disguising traffic as Facebook communications to evade detection.
The campaign also deployed cryptocurrency clipboard hijackers known as AnimateClipper and ZigClipper. These tools monitor the clipboard to replace legitimate wallet addresses with attacker-controlled ones when users copy and paste them. Researchers observed 36 changes to command-and-control domains between March and July 2026, facilitated by Binance Smart Chain contracts, allowing the attackers to switch infrastructure as domains were taken down.
Reddit acknowledged that a corporate account used for advertising was breached to host malicious links. In a statement to CyberGuy, the company said it secured the compromised profile, deleted the harmful ads, and is collaborating with HBO Max to improve security measures. Reddit noted that it has not found evidence of similar breaches affecting other advertising accounts on its platform. HBO Max did not respond to requests for comment before publication.
The prevalence of ClickFix has grown significantly; Huntress reported that the technique accounted for 53% of malware loader activity it observed during 2025. While Apple has added protections in macOS Tahoe 26.4 that warn users when pasted text resembles harmful commands, experts note that these warnings may not catch every malicious attempt. Users are advised to verify software downloads by visiting official websites or app stores directly rather than clicking ads, and to close any page requesting they paste unfamiliar commands into system utilities like Terminal or PowerShell.