Hijacked HBO Max Reddit Ads Push ClickFix Malware

Malwarebytes · High sophistication
Last updated September 15, 2026

Researchers reported that criminals hijacked HBO Max’s verified Reddit account and used it to run malicious ads that led people to fake download sites. The sites didn’t provide real installers, instead they tricked users into pasting and running commands in Terminal/PowerShell, causing them to infect their own device. The campaign (dubbed “PasteSwitch”) delivered information-stealing malware and crypto-focused clipboard hijackers.

Key findings

  • Attackers hijacked HBO Max’s verified Reddit account and ran 108 malicious ads over ~48 hours.
  • Ads promoted fake AI tools, developer software, and macOS utilities, leveraging a trusted brand to reduce suspicion.
  • Victims were sent to convincing lookalike sites and instructed to paste/run commands in Terminal (macOS) or Run/PowerShell (Windows), a ClickFix-style workflow.
  • The operation was dubbed “PasteSwitch” and appeared to tailor payloads based on device type and lure.
  • Observed payloads included AMOS and MacSync infostealers on macOS and the Amatera infostealer on Windows, plus crypto clipboard hijackers.

Who’s being targeted

  • Commonly targeted roles: All employees, Developers, IT, Finance (crypto/clipboard risk awareness), Mac users, Windows users.
  • Affected industries: Media and entertainment, General consumers, Software/developer communities (via developer-tool lures).
  • Attack channels: website.
  • Impersonated: HBO Max (lookalike download site), Trusted software/tool download page (from an ad tied to a verified brand account).

Awareness takeaways

  • Treat ads and ‘verified’ accounts as untrusted; go to the official site directly for downloads.
  • Never run copy‑paste commands from websites/ads (Terminal/PowerShell/Run) unless you fully trust and understand them.
  • Recognize ClickFix: ‘CAPTCHA/verify/fix error’ steps that instruct you to paste a command are a common malware delivery trick.
  • Use layered protection (web blocking, clipboard protection warnings, and endpoint anti-malware) to stop malicious sites and payloads.

Red flags to watch for

  • A software download page provides no installer and instead instructs you to run Terminal commands
  • Brand lookalike site reached via an ad rather than the official site
  • Site behavior that copies commands to the clipboard and tells you to paste them
  • A ‘verification’ or ‘fix’ step that requires running commands on your computer
  • Pressure to act quickly or follow step-by-step instructions without explanation
  • Download initiated from an ad, even if it appears to be from a verified account
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: you’re on Reddit, you see a legit-looking HBO Max ad offering a “native macOS app” promo download, and it’s from a verified HBO Max account. In the PasteSwitch campaign, criminals hijacked HBO Max’s verified Reddit account and pushed over a hundred ads to fake download sites. Instead of an installer, the site tells you: open Terminal or PowerShell and paste this command to install or fix the app. That’s ClickFix: the page silently copies a command, then walks you through pasting and running it so you infect yourself with infostealers like AMOS, MacSync, or Amatera, plus crypto clipboard hijackers. The only real “install” is malware. Here’s the move: if any download page or ad tells you to open Terminal, PowerShell, or Run and paste a command, stop and close it. Then go to the official site yourself if you still need the app.

Similar attacks

HBO Max Reddit Account Hijacked for ClickFix Malware Ads

HBO Max Reddit Account Hijacked for ClickFix Malware Ads

Attackers took over the verified official HBO Max Reddit account and used it to run a 48-hour wave of malicious ads. The ads sent people to lookalike download sites that tricked them into copying and running commands, leading to information-stealing malware on both macOS and Windows. Researchers…

September 15, 2026
HBO Max Reddit Hijack Pushed ClickFix Malware

HBO Max Reddit Hijack Pushed ClickFix Malware

Attackers took over the verified HBO Max Reddit account and ran over 100 malicious ads that sent people to fake download pages. The pages used a ClickFix-style trick: users were told to copy/paste a command into macOS Terminal (and similar OS-targeted lures) to install information-stealing malware.

September 14, 2026
Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026
Odyssey Piracy Lures Push Fake Fixes and EXE “Movies”

Odyssey Piracy Lures Push Fake Fixes and EXE “Movies”

Scammers quickly set up fake piracy pages for Christopher Nolan’s “The Odyssey” to trick people into either clicking a fake browser “Fix It Now” warning or downloading a “movie” that is actually a Windows program. The goal is to route victims through malicious advertising redirects or get them to…

July 20, 2026
“Adult TikTok” Search Lures Drive Scam Funnels

“Adult TikTok” Search Lures Drive Scam Funnels

Scammers are using fake webpages that appear in search results for “TikTok” plus adult terms, promising “exclusive” explicit videos. Instead of any real content, the pages push visitors into an ad/affiliate funnel that collects emails, payment cards for fake “age verification,” or tricks people…

August 3, 2026
Fake Claude Download Page Led to SectopRAT

Fake Claude Download Page Led to SectopRAT

Attackers abused Anthropic’s Claude “Artifacts” publishing feature to host a convincing fake Claude download page on the real claude.ai domain. Victims found it via a sponsored Bing ad, clicked “Download,” and were redirected to attacker-controlled sites that delivered the SectopRAT remote access…

July 23, 2026