Security News

Compromised HBO Max Reddit Account Used to Spread Malware via Fake App Ads

The Register · 15 Sept 2026
Key Takeaway Never copy and paste commands into your computer's terminal or command prompt from a website or ad, no matter how legitimate the source appears, as this is a common trick used to install malware.

The official HBO Max Reddit account was compromised and used to distribute more than 100 malicious ads as part of what researchers call a 48-hour 'malvertising blitz'. The ads promoted a fake macOS app for HBO Max, a client the streaming service does not actually offer, and directed clicks to a convincing lookalike website.

Visitors who clicked through were prompted to copy and paste a command into their Mac's Terminal, a classic 'ClickFix' technique used to trick users into manually running malicious code that bypasses normal security warnings. Reddit paused the ads after being alerted and said its safety teams were investigating, but it is not yet known how the HBO Max account was taken over.

Security researchers at Hudson Rock and ADAMnetworks say the incident was part of a broader campaign, dubbed PasteSwitch, that pushed 108 different malicious ads tailored to victims' operating systems. Payloads included infostealers, malware loaders, fake cryptocurrency wallet apps, and cryptocurrency 'clippers' that hijack transactions, some of which used blockchain smart contracts to keep their command servers running even if taken down.

malvertising ClickFix infostealer social media security macOS malware

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.