HUDSON Rock researchers say cybercriminals hijacked HBO Max’s verified Reddit account and used it to publish 108 malicious advertisements over approximately 48 hours. The adverts promoted fake AI tools, developer software and macOS utilities, using the account’s trusted status to make them more convincing.
Some led to HBO lookalike websites claiming to offer a native macOS app or promotional download, but instead instructed visitors to open Terminal on macOS, or the Run dialogue or PowerShell on Windows, and paste in a command.
The technique, known as ClickFix, disguises malicious instructions as routine steps such as fixing an error, completing a CAPTCHA or installing software. Researchers at ADAMnetworks call this campaign “PasteSwitch” and say its infrastructure appears to select later-stage payloads based on the visitor’s device and lure.
Observed macOS payloads included MacSync and AMOS infostealers, which can target browser credentials and profiles, Telegram data, Apple Notes, saved passwords and cryptocurrency-wallet recovery phrases. Windows users could receive the in-memory Amatera infostealer. The operation was also linked to cryptocurrency clipboard hijackers that replace copied wallet addresses with attacker-controlled ones. Reddit administrators paused the adverts and opened a security investigation after receiving reports.
Users should avoid running commands copied from adverts or untrusted websites, even when content appears to come from a verified account, and should obtain software directly from official websites. macOS Tahoe 26.4 or later may warn when text is pasted into Terminal, but the article says this warning is not universal.