HBO Max Reddit account compromised to serve ClickFix attacks

The official HBO Max Reddit account was compromised to distribute malicious advertisements as part of a larger 'PasteSwitch' malvertising campaign. These ads targeted Windows and macOS users by tricking them into running terminal commands that install information-stealing malware.
Why it matters
This incident highlights the vulnerability of verified corporate social media accounts and the increasing sophistication of malvertising attacks targeting end-users.
Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware
Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware.
A Reddit user uncovered the infostealer ads on September 6, noting that the ad showed u/hbomax as the author — this is the verified HBO Max account — and advertised a macOS app for HBO Max. The streaming service does not offer a native client for the Mac.
Anyone who clicked on the malicious ad would then be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button.
Clicking the button produced instructions telling the user to copy and paste a command into Terminal on macOS.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in