Home / News EN / HBO Max Reddit Account Hacked for ClickFix Attack

HBO Max Reddit Account Hacked for ClickFix Attack

ClickFix attack HBO Max. Cybercriminals took control of the official HBO Max account on Reddit and used it to distribute malware through deceptive advertisements, exploiting a technique known as a “ClickFix” attack. The ultimate goal is the installation of infostealers capable of compromising Windows and macOS operating systems.

ClickFix attack HBO Max

According to reports from Bleeping Computer, the malicious ads were removed after being reported by a user. This user noticed an advertisement on HBO Max’s Reddit account promoting the existence of a native application for macOS. Currently, access to the HBO Max streaming service on Mac devices is possible exclusively via web browser, making the ad potentially misleading and intended to attract users’ attention.

ClickFix attack HBO Max: why it matters

By clicking on the fraudulent advertisement, users were redirected to a fake website. Subsequently, they were presented with a screen requesting them to execute malicious commands within the macOS Terminal. Analysis conducted by researchers at Hudson Rock and ADAMnetworks revealed that cybercriminals published at least 108 advertisements over a period of 48 hours.

This attack is part of the broader “PasteSwitch” campaign, targeting Windows and macOS systems. In this context, specific malware was distributed, including MacSync – an infostealer capable of stealing credentials from web browsers, Firefox profiles, data stored on Telegram, and macOS account passwords – and AMOS Helper, designed to ensure malware persistence on the compromised system and establish a connection with servers controlled by cybercriminals. The criminals also disseminated counterfeit applications mimicking legitimate software such as Ledger, Trezor Suite, and Exodus, with the intent of stealing “seed phrases” (recovery phrases) used to access cryptocurrency wallets.

What changes and what are the effects

It is not yet known how cybercriminals managed to gain access to HBO Max’s Reddit account. Neither HBO nor Warner Bros. Discovery has issued official comments regarding the incident. The PasteSwitch campaign exploits victims’ unwitting actions, asking them to verify CAPTCHAs or install software before inducing them to execute harmful commands via Windows Run, PowerShell, or the macOS Terminal, thereby bypassing operating system protections.

Source and further reading on ClickFix attack HBO Max: original article.

* Content created with the assistance of artificial intelligence systems.