Threats · 4h ago
SecurityWeek says a compromised verified HBO Max Reddit account was used in a 48-hour malvertising run tracked as PasteSwitch, pushing 108 malicious ads across five lure groups. The ads led users to a fake HBO Max site and a ClickFix page that told them to copy a command into Terminal or PowerShell and run it.
That shifts execution out of the browser and into a trusted local tool, so the victim effectively launches the malware themselves. On macOS the chain used curl and zsh; on Windows it used MSHTA and PowerShell, with payloads aimed at stealing credentials, messages, browser data, and cryptocurrency wallets, and at keeping access.
The lasting risk is not just the compromised social account but the trust path it opened: if your users treat copy-paste commands as normal web content, browser-only defenses miss the moment that matters. For teams running brand accounts or watching endpoint abuse, the question is whether a verified account can still be turned into an execution prompt on your users' machines.
1 source covering this story
Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack
Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware.
Part of the PlainSec briefing for 2026-09-15