Hackers breached HBO Max’s official Reddit account and used it to distribute ClickFix malware targeting both Windows and macOS operating systems through malicious ads.
ClickFix is a malware delivery technique that uses social engineering tactics to trick victims into executing malicious programs or commands by convincing them they are fixing a certain problem or installing legitimate software.
The cross-platform campaign monitored the victim’s operating system to determine the appropriate payload to deliver and used blockchain to rotate burned domains.
HBO’s official Reddit account used to distribute ClickFix malware
Dubbed PasteSwitch, the campaign was observed by Hudson Rock and ADAMnetworks and targeted HBO’s official Reddit account u/hbomax. Within 48 hours, the compromised Reddit account had displayed 108 malicious adverts.
According to the researchers, the adverts either impersonated the streaming service, promoted fake AI tools, or purported to deliver legitimate software tools and utilities. However, it delivered info stealers, malware loaders, crypto clippers, and fake crypto wallets.
“This incident demonstrates how attackers are increasingly weaponizing trust rather than relying purely on technical exploitation,” said Ensar Seker, CISO at SOCRadar. “A malicious advertisement coming from a random account immediately raises suspicion, but an advertisement associated with a verified HBO Max account carries an implicit level of legitimacy. Once attackers compromise a trusted brand identity, they effectively inherit that trust and can use it as part of the social-engineering attack chain.”
One of the adverts promoted a macOS HBO Max app, which does not exist. Upon clicking the malicious advert, the victim was redirected to a legitimate-looking hbomaxx[.]us containing a join or download button. When the visitor clicks the button, the website displays commands that the user should run on the terminal to install the app.
According to Hudson Rock, the command downloads MacSync infostealer from hacker infrastructure ember-bridge[.]com. The stealer extracts macOS passwords, browser credentials, Firefox profiles, Telegram data, and Apple Notes.
The campaign also installed AMOS helper, which enrolls compromised devices on the attacker-controlled command-and-control (C2 ) server to receive additional commands via Binance Smart Chain (BSC).
“Because the C2 domain is hosted directly on the blockchain, the infrastructure demonstrates dynamic resilience, allowing the threat actors to easily rotate burned domains,” Hudson Rock wrote.
The malvertising campaign also pushed Ledger, Trezor Suite, and Exodus cryptocurrency wallet applications on the macOS platform. It also delivered developer-tool to target software developers, fake disk-cleaner, and AI-themed malware, such as fake OpenAI Codex.
The attackers used malicious domains codex-craft[.]com, apple.clean-disk-guide[.]com, code-desktop[.]com, and hbomax-macos[.]com to deliver the malware.
On Windows, the attackers instructed the victim to execute commands using MSHTA and PowerShell to evade browser-level detection. The commands create scheduled tasks, deactivated Microsoft’s Antimalware Scan Interface (AMSI), and loaded Amatera Stealer into memory without saving it on the disk.
They also loaded AnimateClipper, a crypto clipper which replaces copied cryptocurrency wallet addresses with the attacker’s, and ZigClipper, which injects code into other processes, establishes persistence and communicates with the attacker’s C2 infrastructure.
Meanwhile, it remains unclear how the attackers compromised HBO’s Reddit account. Nevertheless, the adverts were paused within three days, and HBO has successfully recovered its Reddit account and resumed normal posting.
Another malvertising campaign
PasteSwitch is a traditional ClickFix malvertising campaign leveraging a compromised HBO Reddit account. Similar campaigns have appeared in the past.
In 2025, hackers impersonated the Notion brand to deliver DarkGate malware. In the same year, malicious actors employed ClickFix social engineering tactics to deliver Lumma Stealer malware to tens of thousands of users, while another ClickFix malvertising campaign targeted macOS users using fake ChatGPT pages. Other ClickFix malvertising campaigns include MakeMoney (2022) and FakeBat (2024).

