Threats & Adversaries · Credential Theft

HBO Max Reddit Ads Were Turned Into Malware

Security researchers at Hudson Rock and ADAMnetworks say the verified u/hbomax Reddit account was hijacked and used to run 108 malicious ads over about 48 hours, turning a brand-run ad channel into a malware delivery path. The ads led to fake HBO Max pages that pushed ClickFix and PasteSwitch lures.

ClickFix works by making the victim copy a command into Windows Run, PowerShell, or macOS Terminal; when they paste and press Enter, the machine runs attacker code and installs info-stealers or clippers. Because the command is executed through normal system tools, some browser and download defenses never see a classic malware file arrive first.

For any team that buys ads or manages verified social accounts, the exposure is the trust channel itself: a compromised advertiser account can instantly convert brand reputation into broad reach. If users can see and click those ads, the cleanup problem is not limited to one landing page or one platform account.

2 sources · 5h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-14

Every edition of this story: HBO Max Reddit Ads Were Turned Into Malware

More from today