In brief

  • HBO Max’s hijacked Reddit account ran 108 malicious ads over roughly 48 hours.
  • Malwarebytes linked the ads to PasteSwitch, an operation targeting Windows and Mac users with information-stealing malware.
  • Reddit paused the ads and opened an investigation; victim counts and cryptocurrency losses remain unconfirmed.

Hackers hijacked streaming service HBO Max’s verified Reddit account earlier this month and used it to run 108 malicious advertisements over two days, cybersecurity experts warn.

In its report on Monday, researchers from cybercrime intelligence firm Hudson Rock link the account takeover to a broader operation targeting passwords and cryptocurrency wallet information.

Myriad: Who will be the top Spotify artist of 2026? Click to make your prediction.
Myriad: Who will be the top Spotify artist of 2026? Click to make your prediction.

“The incident was brought to light by Alex Cutts in the r/cybersecurity subreddit. While browsing the platform, they encountered an official Reddit advertisement authored by the verified u/hbomax account,” Hudson Rock wrote. “The ad aggressively promoted a native macOS application for HBO Max, a standalone application that does not currently exist.”

Instead of providing an installer, the site instructed visitors to open Terminal on a Mac, or Run or PowerShell on Windows, and paste a command that could infect their computer.

The technique, known as ClickFix, disguises malicious commands as routine steps for installing software, fixing errors, or proving a visitor is human. The hijacked account gave those instructions the apparent backing of a recognizable company.

Researchers dubbed the operation “PasteSwitch,” warning that its delivery system appears to adapt to the visitor’s device and the software being advertised.

Observed Mac payloads included MacSync and Atomic macOS (AMOS), information-stealer malware designed to steal sensitive information. Reported targets included browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases.

“These clippers utilized Binance Smart Chain (BSC) contracts as mutable C2 dead drops,” researchers wrote, explaining that the malware checks Binance Smart Chain contracts for the latest address of the hackers’ control server. Hackers can then update that address when they switch servers, allowing the malware to keep finding them.

The broader operation was also linked to cryptocurrency clipboard hijackers, which replace a copied wallet address with one controlled by an attacker. A victim who pastes the substituted address without checking it could send funds to the wrong recipient. Stolen recovery phrases pose a separate risk because they can give attackers control of the associated wallet.

According to cybersecurity firm Malwarebytes, Reddit administrators paused the advertisements and opened a security investigation after receiving reports. The report did not establish how the account was compromised or how many people were infected. It described a Reddit account takeover, with no evidence presented of a breach of HBO Max’s streaming service.

ClickFix has appeared in other recent campaigns targeting cryptocurrency users. In August, researchers identified nearly 2,000 compromised WordPress websites supporting a malware operation that used fake verification prompts and could steal wallet information.

Microsoft researchers also described a separate campaign using fake CAPTCHAs to trick Windows users into running malicious commands, with instructions retrieved through BNB Chain.