READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Hackers Hijacked HBO Max's Verified Reddit Account, Ran 108 Malware Ads Before Anyone Caught It

Hackers Hijacked HBO Max's Verified Reddit Account, Ran 108 Malware Ads Before Anyone Caught It
A verified HBO Max Reddit account got hijacked and used to push 108 fake ads over 48 hours, tricking Windows and Mac users into pasting malicious commands into their own terminals. Researchers at Hudson Rock and ADAMnetworks tie it to a bigger operation called PasteSwitch. Reddit says it locked the account and pulled the ads, but hasn't said how many people got infected, and Warner Bros. Discovery still hasn't commented.

A hijacked, verified Reddit account belonging to HBO Max spent roughly 48 hours in early September 2026 running 108 fake advertisements that tricked users into infecting their own computers, according to research from Hudson Rock and ADAMnetworks. Reddit confirmed to TechCrunch that the u/hbomax account, which was authorized to run ads on the platform, had been compromised. The company said it locked the account and removed the ads after learning of the breach.

The scam started with an ad promoting what looked like a native macOS app for HBO Max. There's a problem with that: HBO Max doesn't make a standalone Mac app, according to Bleeping Computer. A Reddit user named Alex Cutts spotted the ad, followed it to a convincing but fake site at hbomaxx[.]us, and posted a warning to the r/cybersecurity subreddit describing exactly what happened next.

"Clicking these opens up the classic infostealer/clickfix paste this command to download," the user wrote, according to Bleeping Computer. "Having checked, this downloads an executable with other capabilities for account compromise."

How ClickFix Actually Works

This is the trick known as ClickFix, and it's become one of the fastest-spreading malware techniques of 2026. A fake or hacked website shows what looks like a normal CAPTCHA or "verify you're human" checkbox. Instead of a real verification, it displays a block of text and instructs the visitor to copy it and paste it into the Windows Run box, PowerShell, or the Mac Terminal, then hit enter.

Doing that installs information-stealing malware capable of grabbing saved passwords, logged-in accounts, and cryptocurrency wallets immediately, according to TechCrunch. Because the user runs the command themselves inside the operating system's own tools, the attack often slips past antivirus software that's built to catch downloaded files, not typed commands.

Independent security researcher Kevin Beaumont said Reddit has become "post after post after post of people getting their computer infected via ClickFix," and that legitimate websites are getting hacked across the internet just to serve the fake prompts, as reported by Ars Technica and HotHardware. Security firm BlueVoyant told Ars Technica that malware operators pivoted hard into ClickFix in late May 2026 specifically because it removes the need for stolen code-signing certificates and rotating malicious domains. The attacker just needs a compromised webpage and a gullible visitor.

A Bigger Operation Called PasteSwitch

Hudson Rock and ADAMnetworks say the HBO Max hijack wasn't a one-off. It's one piece of a larger, coordinated campaign they've named PasteSwitch, which spans Windows loaders, macOS stealers, and cryptocurrency-clipping malware controlled through smart contracts. Beyond HBO Max, the same infrastructure pushed ads impersonating AI tools, developer software, and disk-cleaning utilities, according to the joint research.

The researchers describe a backend built with separate systems for luring victims, qualifying who they are, staging payloads, and exfiltrating stolen data, then dynamically switching the payload depending on whether the visitor is running Windows or macOS. This operation shows a level of sophistication typical of professional criminal organizations. It's an assembly line.

The technique isn't limited to freelance criminals. TechSpot reports that Russian state-sponsored hacking groups have folded ClickFix into their own operations, and fake CAPTCHA prompts have turned up embedded in Google Sheets documents and blockchain smart contracts.

Who's Accountable Here

Warner Bros. Discovery, which owns HBO Max, did not respond to requests for comment from either TechCrunch or Bleeping Computer. Reddit hasn't disclosed how many users clicked the fake ads or how many were compromised. A verified corporate advertiser account ran 108 malicious ads for two straight days before it got caught, which raises a fair question about how closely Reddit's ad-verification system actually watches accounts it has already approved to run paid placements.

There's also a fair pushback on blaming the victims here. Ars Technica argues that everyday computer use has gotten so cluttered with CAPTCHAs, forced pop-ups, and shifting interfaces that ordinary users have grown numb to instructions that would have looked absurd a decade ago. That's a real point. Copying and pasting text into a box isn't something most non-technical users would recognize as dangerous, especially when the request comes wrapped in the branding of a company they trust.

Still, personal responsibility matters. Nobody but the user hits enter. Beaumont's advice for organizations is straightforward: businesses running fleets of Windows machines can disable the Run dialog and PowerShell access entirely through Group Policy. HotHardware notes attackers have already found a workaround called TerminalFix, which asks victims to open PowerShell through the Windows power-user menu instead, meaning the fix isn't permanent. Mac users have a narrower option: a free tool called BlockBlock, highlighted by Ars Technica, that flags unauthorized terminal activity before it runs.

Neither Reddit nor Warner Bros. Discovery has said whether any HBO Max subscriber accounts, payment information, or crypto wallets were actually compromised as a result of the 108 ads. That number, if it ever gets disclosed, will say a lot more about the real damage than the headline hack itself.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchClickFix attacks are tricking Mac and Windows users into hacking themselves
center-left
Ars TechnicaClickFix attacks infecting PCs and Macs are going viral
unknown
TechSpotFake CAPTCHAs are tricking people into hacking their own computers, and it's working
unknown
libresteinforma.com.arClickFix assaults are tricking Mac and Home windows customers into hacking themselves
unknown
infostealersHBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation
unknown
Bleeping ComputerHackers hijack HBO Max Reddit account to push malware in ClickFix ads
unknown
hothardwareClickFix Malware Is Going Viral, Infecting PCs And Macs With CAPTCHA Prompts