> Back to All Posts

Attackers Hijack HBO Max Reddit Account in Malware Ad Scheme

HBO Max Reddit account

Hackers took over the verified Reddit account that HBO Max uses to talk with fans, and they turned it into a malware tool. Over about two days, the hijacked profile ran 108 fake ads. Anyone who clicked risked infecting a Windows PC or Mac with programs that steal passwords, files, and crypto. Because the ads came from a trusted brand with a verified badge, most of the usual red flags never showed up.

How Hackers Used HBO Max’s Reddit Account

A Reddit user first spotted the scam while he scrolled through his feed. He saw an ad from HBO Max’s official Reddit account for a Mac app he had never heard of. The profile looked real, since it had a verified badge and a long posting history in official HBO Max subreddits. So he took a closer look, and what he found sent him to a security forum to warn others.

The ad led to a fake site called hbomaxx[.]us, which copied the look of the real service. It had a join button and a download link, but neither one gave him an app. Instead, the page told him to open Terminal and paste in a command. He tested it in a safe sandbox and found that it grabbed a program built to take over accounts.

Security firms Hudson Rock and ADAMnetworks later looked into the case. They found that attackers had seized the HBO Max account on Reddit and used it to run ads at scale. Reddit staff paused the ads after users flagged them and sent the case to the site’s safety team. Still, nobody knows how the attackers got in, and HBO’s parent company has not answered questions.

What Is a ClickFix Attack?

The ads from HBO Max’s Reddit account used a trick called ClickFix, which fools people rather than software. A fake page claims you must fix an error, pass a CAPTCHA, or install an app. It then asks you to paste a command into Windows Run, PowerShell, or the Mac Terminal. Once you press Enter, the malware installs itself with tools that already sit on your computer.

Criminals like this method because the victim runs the bad command by hand. As a result, some browser shields and security tools never see a risky download. On Mac, the attackers also hid their command with Base64 code, so it looked like random text. Few people would guess that the text pulled a harmful script from a remote server.

A Bigger Scheme Behind the Ads

Researchers tied the attack to a wider campaign they call PasteSwitch. It targets both Windows and Mac users, and its backend swaps the payload and theft method based on who visits. That setup lets one scheme reach very different victims at once.

Only some of the ads from the HBO Max account on Reddit posed as the streaming service. Others pushed fake AI tools, coding software, and Mac cleanup apps. In total, 40 ads led to hbomaxx[.]app, 36 to codex-craft[.]com, 15 to apple.clean-disk-guide[.]com, 11 to code-desktop[.]com, and six to hbomax-macos[.]com. So the attackers reached coders and AI fans as well as TV viewers.

Threats Aimed at Mac Users

Mac owners who clicked through from the HBO Max account on Reddit could end up with MacSync. This malware grabs saved browser logins, Firefox profiles, Telegram data, Apple Notes, and Mac passwords. Another chain dropped a tool called AMOS helper, which hides in a folder named to look like an Apple system file. It then links the Mac to attacker servers, so the criminals can send it new orders.

Threats Aimed at Windows Users

On Windows, the fake pages told victims to run commands through mshta and PowerShell, two tools built into the system. In one chain, a file that acted as both an MP3 and a script set up a scheduled task. It then turned off a Microsoft feature that helps security tools spot harmful scripts. Later, it loaded a password thief called Amatera Stealer straight into memory.

Crypto Wallets in the Crosshairs

Crypto owners faced their own risk, as the campaign spread fake Ledger, Trezor Suite, and Exodus wallet apps that steal recovery phrases. It also pushed two clipboard hijackers, AnimateClipper and ZigClipper, which can swap a copied wallet address for one the attackers own. One careless paste could send your funds straight to the thieves.

How to Stay Safe From ClickFix Scams

Since criminals could seize a verified brand like the HBO Max account on Reddit, you need habits that do not depend on who posted an ad. The key rule is simple: no real site or app will ask you to paste a command into Terminal, PowerShell, or the Run box. If a page asks, close it. Also, get streaming apps only from official app stores, and check each web address before you click.

A VPN can add one more layer, since NordVPN, Surfshark, and some other providers include tools that block known malicious sites. That filter may stop a fake download page before it loads. But it cannot help once you run a harmful command yourself. So keep your system and security software up to date too.

Brands should also learn from what happened to the HBO Max account on Reddit and lock down their social profiles. Strong, unique passwords and app-based two-factor login make takeovers much harder. Regular checks of active sessions and linked apps can also catch an intruder early.

Final Thoughts

The hijack of HBO Max’s Reddit account turned a trusted name into bait for a large malware scheme. In just two days, attackers ran over a hundred ads aimed at TV fans, coders, and crypto holders on Windows and Mac. Reddit paused the ads, but it is still unclear how the criminals got in or what else they reached. Until those answers come, never paste commands from a website, and treat every surprise download offer with suspicion.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.