www.securityweek.com 15 Sept 2026, 09:09 UTC

Hackers Hijack HBO Max’s Reddit Account to Push Mac Malware

Hackers Hijack HBO Max’s Reddit Account to Push Mac Malware
CyberSIXT Evidence Panel Source marked as original reporting

HACKERS compromised HBO Max’s verified Reddit account, _u/hbomax_, and used it to run a malvertising campaign called PasteSwitch. Over a 48-hour period, they published 108 malicious adverts across five lure groups, targeting both macOS and Windows users. The adverts promoted a supposed native HBO Max application for macOS, although no such official app exists, and directed users to hbomaxx[.]us, a fraudulent site imitating HBO Max.

The site’s download button triggered a “ClickFix” prompt instructing victims to copy a command, open Terminal, paste it and run it. ADAMnetworks said this shifted execution from the browser to trusted system utilities controlled by the victim. On macOS, `curl | zsh` commands delivered MacSync, AMOS Helper, fake cryptocurrency-wallet applications and other malware capable of stealing credentials, messages, browser data and wallet information, while establishing persistence.

Windows infections used MSHTA and PowerShell to install Amatera Stealer and maintain access; the malware reportedly spoofed Facebook connections to conceal command-and-control traffic.

HudsonRock also identified AnimateClipper and ZigClipper, persistent clipboard-replacement tools that change cryptocurrency addresses during transactions. The security firms said these stealers used command-and-control infrastructure hosted on the blockchain, apparently established more than a year ago and used in attacks since early 2026. Reddit was notified and immediately suspended the adverts. SecurityWeek said it had asked Warner Bros., which owns HBO Max, for comment, but no response was included.

View full article

Article by CyberSIXT