The hijacking of HBO Max’s verified Reddit account to distribute malicious advertisements is a striking example of how cybercriminals are increasingly weaponizing trust rather than relying only on obviously suspicious websites, unknown senders or poorly disguised phishing messages. Security researchers found that the compromised account was used to launch 108 malicious advertisements over roughly 48 hours, with some ads impersonating HBO Max itself while others promoted fake AI tools, developer utilities and macOS software. The important lesson is that the effectiveness of the campaign did not depend purely on technical sophistication, because the attackers were able to borrow the credibility of a globally recognized brand and a verified social-media identity, making malicious content appear significantly more trustworthy than it would have if it originated from an unknown account. Users have been conditioned to look for familiar brands, verification badges and established profiles when deciding whether online content is legitimate, but this incident demonstrates that these signals can become liabilities once the underlying account is compromised.

The campaign used the increasingly common ClickFix technique, which relies on convincing victims to execute malicious commands themselves instead of silently exploiting a vulnerability in the browser or operating system. Victims were redirected to convincing fake websites and instructed to open Windows Run, PowerShell or macOS Terminal and paste commands under the pretence of fixing an error, installing legitimate software or completing a verification step. This is particularly effective from an attacker’s perspective because the user becomes part of the execution chain, while legitimate operating-system tools perform the malicious actions. Traditional security controls are often designed to identify suspicious downloads, malicious executables or browser-delivered payloads, but ClickFix techniques deliberately move execution into trusted system utilities, potentially allowing parts of the attack to blend into normal administrative activity. The broader challenge for defenders is therefore no longer simply detecting malicious files, but identifying legitimate tools being used in an illegitimate context.

The campaign, linked by researchers to a larger operation known as PasteSwitch, also demonstrates how modern malware delivery has become highly adaptive. Rather than relying on a single lure or payload, the infrastructure could reportedly switch between different campaigns, operating systems, malware families and cryptocurrency theft methods depending on the visitor. The attackers targeted both Windows and macOS users and distributed information stealers, loaders, clipboard hijackers and fake cryptocurrency wallet applications, showing that cross-platform attacks are becoming increasingly practical and commercially attractive. On macOS systems, one observed infection chain delivered malware capable of stealing browser credentials, Firefox profiles, Telegram information, Apple Notes and macOS passwords, while other payloads were designed to establish persistence and receive further instructions from attacker-controlled infrastructure. On Windows, the campaign used tools such as PowerShell and mshta, with later stages involving obfuscated code and in-memory malware execution designed to reduce the number of obvious malicious artifacts written to disk.

The attack also highlights the growing importance of information stealers in the cybercrime ecosystem. Infostealer malware is often treated as a relatively simple endpoint threat, but stolen browser credentials, authentication cookies, session tokens, cryptocurrency wallet information and stored passwords can become the starting point for much larger compromises. A single infected personal or corporate device may provide attackers with access to email accounts, SaaS applications, development platforms, cloud consoles, financial services or even administrative systems. Those stolen credentials can subsequently be sold, reused in account takeover attacks or leveraged by other threat groups for ransomware and data theft. In that sense, an advertisement that appears to promote a harmless desktop application can ultimately create an entry point into an entirely unrelated corporate environment if the victim uses the same device for both personal and professional activity.

There is an equally important identity-security lesson in the compromise of the HBO Max Reddit account itself. At the time of reporting, it was still unclear how the attackers gained access to the account or whether other HBO or Warner Bros. Discovery systems were affected, but the incident demonstrates why high-profile corporate social-media accounts should be treated as privileged business assets rather than ordinary marketing channels. Such accounts can reach enormous audiences, carry established brand trust and, in many cases, support paid advertising, which makes them valuable infrastructure for attackers. Organisations should therefore apply strong multi-factor authentication, phishing-resistant authentication where practical, strict controls over account recovery, least-privilege access, centralized credential management and continuous monitoring of changes to advertising campaigns, account settings and login behaviour. The security of a social-media account is no longer merely a reputational concern because a compromised account can become an active malware distribution platform.

The abuse of paid advertising adds another dimension to the problem because users often assume that advertisements shown on major platforms have undergone some level of verification before being displayed. Attackers increasingly exploit this assumption by using compromised advertiser accounts, convincing domains and professionally designed landing pages to make malicious campaigns appear legitimate. In this case, advertisements reportedly redirected users to fake HBO Max and other software-related sites that closely resembled genuine services before presenting the malicious ClickFix instructions. This means advertising platforms need to evaluate much more than the identity of the account purchasing the advertisement, because a previously legitimate and verified advertiser can become dangerous immediately after an account takeover. Sudden changes in advertising volume, destination domains, campaign themes or geographic targeting should therefore be treated as possible indicators of compromise rather than simply normal marketing activity.

The incident is also another warning that verification badges should be interpreted as indicators of identity history rather than permanent guarantees of current trustworthiness. A verified account may have been legitimate when verification was granted, but verification cannot prove that the individual currently controlling the account is still the legitimate owner. This distinction becomes increasingly important as attackers target social-media profiles, developer accounts, advertising platforms and cloud identities specifically because those accounts already possess reputation and trust. Cybersecurity awareness therefore needs to evolve beyond advice such as checking whether an account is verified or whether a website looks professional, because attackers are increasingly capable of compromising the very trust signals users were taught to rely upon.

For organisations, defending against ClickFix-style attacks requires both technical controls and user awareness. Security teams should monitor suspicious use of PowerShell, command shells, mshta and scripting environments, particularly when those processes originate from browsers or occur immediately after users visit unfamiliar domains. Endpoint detection systems should focus on unusual process chains and behaviour rather than relying entirely on malware signatures, while DNS filtering, web reputation controls and application restrictions can help prevent users from reaching known malicious infrastructure. Organisations should also educate employees that legitimate websites rarely require users to copy commands from a browser into PowerShell, Terminal or the Windows Run dialog to verify themselves, repair a browser problem or install routine software. Any workflow asking an ordinary user to manually execute an encoded or unexplained system command should immediately be treated as suspicious.

The wider lesson from this campaign is that modern cyberattacks increasingly succeed by corrupting legitimate trust relationships rather than simply breaking through technical defenses. The advertisement can come from a major platform, the account can carry a verification badge, the brand can be globally recognised, the website can look professional and the commands can run through legitimate operating-system tools, yet the entire sequence can still be malicious. Security architectures therefore need to assume that trusted identities, platforms and applications can occasionally become compromised and continuously evaluate what they are doing rather than relying on who they appear to be. In an environment where attackers can hijack trusted accounts and convince victims to execute the malware themselves, context, behaviour and continuous verification become far more meaningful security signals than reputation alone.


Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]

Source: Hackers hijack HBO Max Reddit account to push malware in ClickFix ads via Bleeping Computer — published 14 Sep 2026.