LIVE · cybersecurity feed
Live wire
malware

HBO Max Reddit account compromised to serve ClickFix attacks

Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware

zeroday.news ·

The official Reddit account for HBO Max, u/hbomax, was compromised and used to distribute over 100 malicious advertisements, serving ClickFix attacks designed to infect both Windows and macOS devices with information-stealing malware. The incident was part of a broader "massive 48-hour malvertising blitz" that researchers have dubbed PasteSwitch.

A Reddit user first identified the malicious ads on September 6, noting that they were attributed to the verified HBO Max account and promoted a non-existent macOS application for the streaming service. Clicking these ads led users to "somewhat-legitimate" looking landing pages, such as hbomaxx[.]us, which featured a download button. For macOS users, clicking this button provided instructions to copy and paste a command into their Terminal, a common method for delivering infostealers. The Reddit user tested this process in a sandboxed environment without executing the final payload.

Three days later, Reddit paused the malicious ads and confirmed that its safety and security teams were investigating the account compromise. Warner Bros. Discovery, HBO Max's parent company, has not yet publicly commented on the incident, including details on how the account was hijacked or by whom.

Security researchers at Hudson Rock and ADAMnetworks analyzed the campaign, identifying 108 distinct malicious ads that leveraged various software lures. The PasteSwitch campaign delivers operating-system-specific malware, including infostealers, malware loaders, cryptocurrency clippers (AnimateClipper or ZigClipper), and fake cryptocurrency wallet applications. The cryptocurrency clippers incorporate blockchain-based command-and-control (C2) fallbacks, utilizing Binance Smart Chain (BSC) contracts to dynamically retrieve current C2 domains. Between March and July 2026, researchers observed 36 mainnet changes executed by the same attacker controller address, indicating a resilient infrastructure that allows threat actors to easily rotate compromised domains.

Beyond the HBO Max lure, the attackers also exploited themes related to developer tools, disk cleaners, and artificial intelligence. This included fake OpenAI Codex ads, a tactic previously used to distribute Mac malware. Of the 108 ads, 46 used an HBO Max theme, directing users to hbomaxx[.]app or hbomax-macos[.]com. Another 36 ads mimicked OpenAI Codex, leading to codex-craft[.]com. Additionally, 15 ads posed as a macOS disk utility (apple.clean-disk-guide[.]com), and 11 others used various developer tool themes (code-desktop[.]com).

The campaign highlights an ongoing trend where trusted distribution channels are increasingly targeted for malware delivery, particularly infostealers. The continued prevalence of ClickFix attacks underscores the effectiveness of this social engineering method for threat actors.

malwarepatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s