CYBER DELTA FORCESearch
Cyber AttacksDEVELOPING

Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack

Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware.

CDF News DeskSecurityWeek15 Sept 2026, 2:39 pm
Image courtesy of SecurityWeek. Original report
CDF REPORT

Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware. Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Patrick McKinney has joined Turing as Chief Information Security Officer.

Clicking these opens up the classic infostealer/clickfix paste this command to download. One malware family used in this attack is MacSync, which Hudson Rock says steals browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords. Later stages used obfuscated PowerShell and shellcode to load the Amatera Stealer directly into memory without first saving the final payload to disk. It remains unclear how the attackers accessed the HBO Max Reddit account or whether any other HBO or Warner Bros.

One of the macOS commands BleepingComputer saw in this attack used Base64 encoding to obscure the command it executed. Once decoded, it contained the following command: Hudson Rock noted ember-bridge[.]com as infrastructure used in September for malware delivery in the PasteSwitch operation.

What changed

The ads used a social engineering technique known as ClickFix, which tricks users into copying and pasting malicious commands into Windows Run, PowerShell, or macOS Terminal while pretending to fix an error, verify a CAPTCHA, or install legitimate software.

Hudson Rock and ADAMnetworks have linked the attack to a larger campaign they call PasteSwitch, which targets both Windows and macOS systems and has been used to distribute information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications.

The researchers say PasteSwitch refers to the operation's use of attacker-supplied commands that victims paste into their systems, while the attackers' backend switches between campaigns, platforms, payloads, and crypto theft methods depending on the visitor.

Having checked, this downloads an executable with other capabilities for account compromise (obviously all done in a full sandbox - inspecting the output only, not running anything)." One of the fake HBO Max sites used in the campaign was hbomaxx[.]us.

The campaign has also distributed fake Ledger, Trezor Suite, and Exodus cryptocurrency wallet applications designed to steal victims' wallet recovery phrases.

Who is affected

Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.

The type of attack has become increasingly popular among cybercriminals because victims run the malicious commands themselves using legitimate operating system tools, potentially bypassing some browser and security software designed to detect malware downloads.

Another attack chain deployed "AMOS helper," which establishes persistence using a directory named .com.apple.accountsd.

The malware can then enroll infected systems with attacker-controlled servers to receive additional tasks.

Hudson Rock says one Windows attack chain used an MP3/HTA polyglot to create a scheduled task, launch 32-bit PowerShell, disable Microsoft's Antimalware Scan Interface (AMSI), and generate victim-specific infrastructure based on the computer name and username.

This allowed the attackers to target a larger audience than just HBO Max users, including developers and users searching for AI software and system utilities.

Why this matters

Clicking these opens up the classic infostealer/clickfix paste this command to download.

One malware family used in this attack is MacSync, which Hudson Rock says steals browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords.

Later stages used obfuscated PowerShell and shellcode to load the Amatera Stealer directly into memory without first saving the final payload to disk.

It remains unclear how the attackers accessed the HBO Max Reddit account or whether any other HBO or Warner Bros.

The technical picture

One of the macOS commands BleepingComputer saw in this attack used Base64 encoding to obscure the command it executed.

Once decoded, it contained the following command: Hudson Rock noted ember-bridge[.]com as infrastructure used in September for malware delivery in the PasteSwitch operation.

MORE IN CYBER ATTACKS

More cybersecurity reporting

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the PointThe Hacker News · 15 Sept 2026, 4:56 pmInternational Meteor Organization Hit by Cyberattack, Weeks of Disruption ExpectedThe Cyber Express · 15 Sept 2026, 12:35 pmUK Small Firms Bear Brunt of Rising Cyberattacks, Hiscox FindsThe Cyber Express · 15 Sept 2026, 11:39 amNew DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential ComputingThe Hacker News · 14 Sept 2026, 11:32 pm