{
  "id": 7435480,
  "title": "HBO Max Reddit account compromised to serve ClickFix attacks",
  "url": "https://urgent.news/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks",
  "topic": "science",
  "section": "Science",
  "published": "2026-09-14T22:43:01.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408"
  },
  "original_language": "en",
  "account": "On September 6, a Reddit user discovered malicious ads on the official HBO Max Reddit account. The ads showcased a macOS app for HBO Max, despite the streaming service not offering one. Users who clicked on the ad were redirected to a landing page (hbomaxx.us) with a join/download button. Clicking the button prompted users to copy and paste a command into Terminal on macOS, a tactic known as ClickFix. The Reddit user suspected the account had been compromised and reported the issue. Three days later, Reddit paused the ads, and an admin stated that their security and safety teams were investigating.\n\nResearchers at Hudson Rock and ADAMnetworks analyzed the ads and uncovered a \"massive 48-hour malvertising blitz\" called PasteSwitch. The campaign consisted of 108 distinct ads employing multiple software lures, including infostealers, malware loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications. Hudson Rock identified two specific cryptocurrency clippers, AnimateClipper and ZigClipper, which offer blockchain-based command-and-control fallbacks for attackers. These clippers utilize Binance Smart Chain (BSC) contracts to dynamically fetch C2 domains, allowing threat actors to easily rotate burned domains, ensuring dynamic resilience.\n\nThe attackers employed various lures, targeting HBO Max accounts, developer tools, disk cleaners, and AI-themed ads, including fake OpenAI Codex ads. Of the 108 ads, 46 used an HBO Max lure, directing users to hbomaxx.app or hbomax-macos.com. Another 36 ads attempted to trick users through an OpenAI Codex theme (codex-craft.com). The remaining ads included 15 macOS disk utility lures (apple.clean-disk-guide.com) and 11 other developer tool lures (code-desktop.com).\n\nAccording to Hudson Rock co-founder and CTO Alon Gal, the campaign highlights the vulnerability of trusted distribution channels to infostealer delivery and the continued heavy use of ClickFix attacks.",
  "summary": "Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "HBO Max Reddit account compromised to serve ClickFix attacks",
        "url": "https://urgent.news/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks-7437754",
        "published": "2026-09-14T22:43:01.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}