Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack
Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware.

Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware. Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Patrick McKinney has joined Turing as Chief Information Security Officer.
Clicking these opens up the classic infostealer/clickfix paste this command to download. One malware family used in this attack is MacSync, which Hudson Rock says steals browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords. Later stages used obfuscated PowerShell and shellcode to load the Amatera Stealer directly into memory without first saving the final payload to disk. It remains unclear how the attackers accessed the HBO Max Reddit account or whether any other HBO or Warner Bros.
One of the macOS commands BleepingComputer saw in this attack used Base64 encoding to obscure the command it executed. Once decoded, it contained the following command: Hudson Rock noted ember-bridge[.]com as infrastructure used in September for malware delivery in the PasteSwitch operation.
What changed
The ads used a social engineering technique known as ClickFix, which tricks users into copying and pasting malicious commands into Windows Run, PowerShell, or macOS Terminal while pretending to fix an error, verify a CAPTCHA, or install legitimate software.
Hudson Rock and ADAMnetworks have linked the attack to a larger campaign they call PasteSwitch, which targets both Windows and macOS systems and has been used to distribute information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications.
The researchers say PasteSwitch refers to the operation's use of attacker-supplied commands that victims paste into their systems, while the attackers' backend switches between campaigns, platforms, payloads, and crypto theft methods depending on the visitor.
Having checked, this downloads an executable with other capabilities for account compromise (obviously all done in a full sandbox - inspecting the output only, not running anything)." One of the fake HBO Max sites used in the campaign was hbomaxx[.]us.
The campaign has also distributed fake Ledger, Trezor Suite, and Exodus cryptocurrency wallet applications designed to steal victims' wallet recovery phrases.
Who is affected
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.
The type of attack has become increasingly popular among cybercriminals because victims run the malicious commands themselves using legitimate operating system tools, potentially bypassing some browser and security software designed to detect malware downloads.
Another attack chain deployed "AMOS helper," which establishes persistence using a directory named .com.apple.accountsd.
The malware can then enroll infected systems with attacker-controlled servers to receive additional tasks.
Hudson Rock says one Windows attack chain used an MP3/HTA polyglot to create a scheduled task, launch 32-bit PowerShell, disable Microsoft's Antimalware Scan Interface (AMSI), and generate victim-specific infrastructure based on the computer name and username.
This allowed the attackers to target a larger audience than just HBO Max users, including developers and users searching for AI software and system utilities.
Why this matters
Clicking these opens up the classic infostealer/clickfix paste this command to download.
One malware family used in this attack is MacSync, which Hudson Rock says steals browser credentials, Firefox profiles, Telegram data, Apple Notes, and macOS passwords.
Later stages used obfuscated PowerShell and shellcode to load the Amatera Stealer directly into memory without first saving the final payload to disk.
It remains unclear how the attackers accessed the HBO Max Reddit account or whether any other HBO or Warner Bros.
The technical picture
One of the macOS commands BleepingComputer saw in this attack used Base64 encoding to obscure the command it executed.
Once decoded, it contained the following command: Hudson Rock noted ember-bridge[.]com as infrastructure used in September for malware delivery in the PasteSwitch operation.