Threats · 4h ago
Security researchers at Hudson Rock and ADAMnetworks say the verified u/hbomax Reddit account was hijacked and used to run 108 malicious ads over about 48 hours, turning a brand-run ad channel into a malware delivery path. The ads led to fake HBO Max pages that pushed ClickFix and PasteSwitch lures.
ClickFix works by making the victim copy a command into Windows Run, PowerShell, or macOS Terminal; when they paste and press Enter, the machine runs attacker code and installs info-stealers or clippers. Because the command is executed through normal system tools, some browser and download defenses never see a classic malware file arrive first.
For any team that buys ads or manages verified social accounts, the exposure is the trust channel itself: a compromised advertiser account can instantly convert brand reputation into broad reach. If users can see and click those ads, the cleanup problem is not limited to one landing page or one platform account.
2 sources covering this story
ClickFix attacks are tricking Mac and Windows users into hacking themselves | TechCrunch
If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising "ClickFix" security threat.
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.
Part of the PlainSec briefing for 2026-09-14