
Hackers hijacked HBO Max's verified Reddit account to run 108 malicious advertisements over two days, using a technique called ClickFix to trick users into installing information-stealing malware targeting passwords and cryptocurrency wallet data, according to cybersecurity researchers from Hudson Rock.
AI-generated summary
Cybersecurity researchers from Hudson Rock reported that hackers hijacked HBO Max's verified Reddit account to run malicious advertisements using the ClickFix technique, which disguises harmful commands as legitimate software installation steps.
Hackers hijacked streaming service HBO Max’s verified Reddit account earlier this month and used it to run 108 malicious advertisements over two days, cybersecurity experts warn.
In its report on Monday, researchers from cybercrime intelligence firm Hudson Rock link the account takeover to a broader operation targeting passwords and cryptocurrency wallet information.
“The incident was brought to light by Alex Cutts in the r/cybersecurity subreddit. While browsing the platform, they encountered an official Reddit advertisement authored by the verified u/hbomax account,” Hudson Rock wrote. “The ad aggressively promoted a native macOS application for HBO Max, a standalone application that does not currently exist.”
Instead of providing an installer, the site instructed visitors to open Terminal on a Mac, or Run or PowerShell on Windows, and paste a command that could infect their computer.
The technique, known as ClickFix, disguises malicious commands as routine steps for installing software, fixing errors, or proving a visitor is human. The hijacked account gave those instructions the apparent backing of a recognizable company.
Researchers dubbed the operation “PasteSwitch,” warning that its delivery system appears to adapt to the visitor’s device and the software being advertised.
Observed Mac payloads included MacSync and Atomic macOS (AMOS), information-stealer malware designed to steal sensitive information. Reported targets included browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases.
“These clippers utilized Binance Smart Chain (BSC) contracts as mutable C2 dead drops,” researchers wrote, explaining that the malware checks Binance Smart Chain contracts for the latest address of the hackers’ control server. Hackers can then update that address when they switch servers, allowing the malware to keep finding them.
The broader operation was also linked to cryptocurrency clipboard hijackers, which replace a copied wallet address with one controlled by an attacker. A victim who pastes the substituted address without checking it could send funds to the wrong recipient. Stolen recovery phrases pose a separate risk because they can give attackers control of the associated wallet.
According to cybersecurity firm Malwarebytes, Reddit administrators paused the advertisements and opened a security investigation after receiving reports. The report did not establish how the account was compromised or how many people were infected. It described a Reddit account takeover, with no evidence presented of a breach of HBO Max’s streaming service.
ClickFix has appeared in other recent campaigns targeting cryptocurrency users. In August, researchers identified nearly 2,000 compromised WordPress websites supporting a malware operation that used fake verification prompts and could steal wallet information.
AI outlook — possibilities, not facts
Reddit will implement stronger security measures for verified accounts following the investigation
Likely · Within weeks

Solana has deployed its V1 transaction format, increasing data capacity per transaction to 4,096 bytes, and is advancing toward 250ms slot times effective Sept. 18, with 200ms targeted next. These upgrades coincide with record network activity, including 5.2 billion non-vote transactions in August and $40.8 million in weekly application revenue.

Circle has launched Arc, a Layer 1 blockchain designed for payments and agentic economic activity. The network uses USDC as its gas token and features a permissioned validator model, supported by major financial partners including BlackRock, Visa, and Mastercard.

The Cato Institute and Block's Jack Dorsey warn that government-mandated AI development pauses may entrench dominant companies, hinder competition, and weaken cybersecurity, suggesting that voluntary standards and independent testing are better alternatives.

Zcash token holders voted to reduce block times from 75 to 25 seconds and maintain existing halving schedules for the NU7 upgrade. The community also overwhelmingly supported delaying the Network Sustainability Mechanism until 2031.

USDC issuer Circle has launched the mainnet of Arc, an EVM-compatible layer-1 blockchain designed for stablecoin payments and agentic economic activity. The network supports over 20 fiat stablecoins and integrates with Circle's existing cross-chain protocols.

Liquidity aggregator 0x reported an alarming rise in malicious Uniswap v4 hooks designed to quote one price and settle at another, with over 80% of analyzed hooks classified as malicious or likely malicious.