The official Reddit account for HBO Max, u/hbomax, was compromised and used to distribute over 100 malicious advertisements, serving ClickFix attacks designed to infect both Windows and macOS devices with information-stealing malware. The incident was part of a broader "massive 48-hour malvertising blitz" that researchers have dubbed PasteSwitch.
A Reddit user first identified the malicious ads on September 6, noting that they were attributed to the verified HBO Max account and promoted a non-existent macOS application for the streaming service. Clicking these ads led users to "somewhat-legitimate" looking landing pages, such as hbomaxx[.]us, which featured a download button. For macOS users, clicking this button provided instructions to copy and paste a command into their Terminal, a common method for delivering infostealers. The Reddit user tested this process in a sandboxed environment without executing the final payload.
Three days later, Reddit paused the malicious ads and confirmed that its safety and security teams were investigating the account compromise. Warner Bros. Discovery, HBO Max's parent company, has not yet publicly commented on the incident, including details on how the account was hijacked or by whom.
Security researchers at Hudson Rock and ADAMnetworks analyzed the campaign, identifying 108 distinct malicious ads that leveraged various software lures. The PasteSwitch campaign delivers operating-system-specific malware, including infostealers, malware loaders, cryptocurrency clippers (AnimateClipper or ZigClipper), and fake cryptocurrency wallet applications. The cryptocurrency clippers incorporate blockchain-based command-and-control (C2) fallbacks, utilizing Binance Smart Chain (BSC) contracts to dynamically retrieve current C2 domains. Between March and July 2026, researchers observed 36 mainnet changes executed by the same attacker controller address, indicating a resilient infrastructure that allows threat actors to easily rotate compromised domains.
Beyond the HBO Max lure, the attackers also exploited themes related to developer tools, disk cleaners, and artificial intelligence. This included fake OpenAI Codex ads, a tactic previously used to distribute Mac malware. Of the 108 ads, 46 used an HBO Max theme, directing users to hbomaxx[.]app or hbomax-macos[.]com. Another 36 ads mimicked OpenAI Codex, leading to codex-craft[.]com. Additionally, 15 ads posed as a macOS disk utility (apple.clean-disk-guide[.]com), and 11 others used various developer tool themes (code-desktop[.]com).
The campaign highlights an ongoing trend where trusted distribution channels are increasingly targeted for malware delivery, particularly infostealers. The continued prevalence of ClickFix attacks underscores the effectiveness of this social engineering method for threat actors.






