Threats · 4h ago

HBO Max Reddit Account Fueled PasteSwitch Malware Ads

SecurityWeek says a compromised verified HBO Max Reddit account was used in a 48-hour malvertising run tracked as PasteSwitch, pushing 108 malicious ads across five lure groups. The ads led users to a fake HBO Max site and a ClickFix page that told them to copy a command into Terminal or PowerShell and run it.

That shifts execution out of the browser and into a trusted local tool, so the victim effectively launches the malware themselves. On macOS the chain used curl and zsh; on Windows it used MSHTA and PowerShell, with payloads aimed at stealing credentials, messages, browser data, and cryptocurrency wallets, and at keeping access.

The lasting risk is not just the compromised social account but the trust path it opened: if your users treat copy-paste commands as normal web content, browser-only defenses miss the moment that matters. For teams running brand accounts or watching endpoint abuse, the question is whether a verified account can still be turned into an execution prompt on your users' machines.

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-15

Editions

Related stories