Security researchers at Hudson Rock and ADAMnetworks say the verified u/hbomax Reddit account was hijacked and used to run 108 malicious ads over about 48 hours, turning a brand-run ad channel into a malware delivery path. The ads led to fake HBO Max pages that pushed ClickFix and PasteSwitch lures.
ClickFix works by making the victim copy a command into Windows Run, PowerShell, or macOS Terminal; when they paste and press Enter, the machine runs attacker code and installs info-stealers or clippers. Because the command is executed through normal system tools, some browser and download defenses never see a classic malware file arrive first.
For any team that buys ads or manages verified social accounts, the exposure is the trust channel itself: a compromised advertiser account can instantly convert brand reputation into broad reach. If users can see and click those ads, the cleanup problem is not limited to one landing page or one platform account.
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.