Hijacked HBO Max Reddit account pushed 108 malware ads in 48 hours
A verified account was used to run a copy-paste scam that infected Windows and Mac users with password stealers and crypto-wallet thieves.

Key points
- Criminals took over the verified u/hbomax Reddit account and ran 108 malicious ads over roughly 48 hours, according to researchers at Hudson Rock and ADAMnetworks.
- The ads used ClickFix, a trick that talks victims into pasting attacker-supplied commands into their own computer to run malware.
- Payloads included the MacSync and Amatera information stealers, plus fake Ledger and Exodus crypto wallet apps built to grab recovery phrases.
- Only 6 of the ads impersonated HBO Max; the rest pushed fake AI tools, developer software and Mac cleanup utilities to widen the target pool.
- Reddit paused the ads after a user reported them; HBO and Warner Bros. Discovery have not said how the account was taken over.
A verified Reddit account belonging to HBO Max was hijacked and turned into a malware delivery service, researchers say, in a campaign that ran 108 sponsored posts across about two days.
The posts looked legitimate. They came from u/hbomax, which had the verified check and a history of posting in official HBO Max communities. That trust was the whole point.
Hudson Rock and ADAMnetworks, who analysed the operation, flagged it after a Reddit user spotted an ad for a "native HBO Max app for macOS" that doesn't actually exist. The report was picked up by BleepingComputer.
What actually happened when someone clicked?
Clicking an ad sent the visitor to a convincing fake site such as hbomaxx[.]us. The download button did not download anything. Instead, the page told the visitor to open Terminal on a Mac or PowerShell on Windows and paste in a command "to install" the app.
That command did the real work: it fetched and ran malware from an attacker server. One Mac example used a Base64-encoded (scrambled) command that pulled a script from ember-bridge[.]com and executed it.
This technique is called ClickFix. Victims run the malicious command themselves using tools that already ship with the operating system, which makes it harder for browsers and antivirus software to spot the download. We've tracked ClickFix across 35 stories since May 2026, and the HBO Max campaign shows the technique maturing: attackers now layer a trusted brand's verified badge on top of the same paste-and-run mechanic.
Which malware ended up on victims' machines?
On macOS, the researchers saw MacSync, which lifts browser logins, Firefox profiles, Telegram data, Apple Notes and macOS passwords. They also saw an "AMOS helper" that hides in a folder named .com.apple.accountsd and phones home for further instructions.
Some chains dropped fake Ledger and Exodus wallet apps designed to capture the recovery phrase that controls a victim's cryptocurrency. Trezor Suite fakes were part of the mix too.
On Windows, pasted commands used built-in tools mshta and PowerShell to set up a scheduled task, disable Microsoft's Antimalware Scan Interface (a hook that lets security tools inspect scripts), and load the Amatera Stealer straight into memory so nothing suspicious was written to disk. We first reported on Amatera in our 25 August story on WordlistLoader. Clipboard hijackers AnimateClipper and ZigClipper, which silently swap a copied crypto address for the attacker's, were also seen.
Was this really about HBO Max fans?
No, and that's the interesting part. Only 6 of the ads pointed to hbomax-macos[.]com. Another 40 pushed hbomaxx[.]app, 36 pointed to fake AI and developer site codex-craft[.]com, 15 sent people to apple.clean-disk-guide[.]com and 11 to code-desktop[.]com.
The researchers call the wider operation PasteSwitch, because a backend server switches the payload and crypto-theft method based on who is visiting. A verified streaming brand was just the delivery van.
Should you worry if you clicked one of these ads?
Yes. Mac users who followed the HBO Max ad should treat browser passwords and Telegram sessions as exposed, change passwords from a clean device, and move wallet funds to a new seed phrase.
If a website ever asks you to open Terminal or PowerShell and paste a command, stop. Legitimate apps don't install that way.
Honest read: MFA wouldn't have saved anyone here, because victims were tricked into running code as themselves. This was social engineering riding Reddit's verified badge, and until platforms treat a compromised verified account as a Sev-1 incident within minutes rather than hours, 48-hour windows like this one will keep paying out.
How the attackers got into the HBO Max Reddit account is still unknown. Session token theft from a prior stealer infection is the boring, likely answer.



