Someone took over the official HBO Max Reddit account and turned it into a malware delivery machine, pumping out 108 malicious advertisements in roughly 48 hours before the campaign was shut down.
The ads directed unsuspecting users to fake websites mimicking HBO Max and other software tools. The endgame wasn’t streaming piracy. It was draining crypto wallets.
How the attack worked
The hijacked account, u/hbomax, carried Reddit’s verified badge, which gave the malicious ads an air of legitimacy that most phishing campaigns can only dream about. Of the 108 ads deployed, 46 were themed around HBO Max specifically, while others posed as downloads for various software tools.
The attackers relied on a social-engineering technique called ClickFix. It’s a method that tricks users into manually executing commands in Terminal on Mac, PowerShell on Windows, or the Run dialog box.
Victims who followed the instructions unknowingly installed infostealers onto their machines. The fraudulent domains included lookalikes such as hbomaxx[.]us and hbomax-macos[.]com, close enough to the real thing that a casual glance wouldn’t raise alarms.
The malware payloads included MacSync and AMOS infostealers, both well-documented tools in the cybercriminal ecosystem.
Crypto wallets were the primary target
While the malware hoovered up the usual targets like browser credentials, saved passwords, and Telegram session data, the crown jewels were cryptocurrency wallet recovery phrases. Seed phrases, typically 12 or 24 words, are the master key to a crypto wallet. Anyone who has them can reconstruct the wallet and transfer everything out.
The attack didn’t stop at stealing seed phrases, either. The malware suite included clipboard hijackers that monitor when a user copies a wallet address and silently swap it for one controlled by the attacker.
Security researchers from Hudson Rock and ADAMnetworks traced this operation back to a broader malware campaign they’ve dubbed PasteSwitch. According to their analysis, PasteSwitch has been active since early 2026, deploying similar deceptive lures across multiple platforms. The HBO Max Reddit takeover wasn’t an isolated stunt. It was one node in a larger, sustained offensive.
Reddit’s response and the trust problem
Reddit eventually suspended the malicious ads after community members flagged them, recognizing that the verified account had been compromised. The platform acknowledged the account’s role as a facilitator of the attacks.
The 48-hour window in this case is notable. The attackers moved fast enough to push 108 ads before Reddit’s moderation caught up, suggesting either automated deployment or a well-coordinated team.
What this means for crypto holders
The ClickFix technique deserves particular attention because it exploits a gap in traditional security software. Antivirus tools are designed to catch malicious downloads and suspicious executables. When the user manually types a command into their terminal, the system treats it as an authorized action. The malware enters through the front door with the user’s own credentials.
The PasteSwitch campaign’s persistence since early 2026 suggests this isn’t a smash-and-grab operation but rather an ongoing enterprise. The PasteSwitch infrastructure allows for quick changes in domains and device-specific payloads, enabling attackers to continue finding new distribution channels.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
16









English (US) ·