Hackers compromised HBO Max’s official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. Security researchers at Hudson Rock and ADAMnetworks analyzed the campaign and say the verified u/hbomax Reddit account was hijacked and used to launch 108 malicious advertisements over about 48 hours.
Commenting on this is Ensar Seker, CISO at SOCRadar:
“This incident demonstrates how attackers are increasingly weaponizing trust rather than relying purely on technical exploitation. A malicious advertisement coming from a random account immediately raises suspicion, but an advertisement associated with a verified HBO Max account carries an implicit level of legitimacy. Once attackers compromise a trusted brand identity, they effectively inherit that trust and can use it as part of the social-engineering attack chain.
ClickFix is particularly effective because the attacker convinces the victim to execute the malicious action themselves. Instead of delivering a conventional executable that security controls may block, the victim is instructed to copy and paste commands into PowerShell, Windows Run, or macOS Terminal. From a detection perspective, this is challenging because legitimate operating-system tools are being used, and the initial execution is performed by the user. In this campaign, researchers observed payloads ranging from information stealers to cryptocurrency theft tools, with targeting across both Windows and macOS.
The larger security lesson is that organizations must treat corporate social-media and advertising accounts as privileged infrastructure. These accounts should have phishing-resistant MFA, tightly controlled administrator access, continuous monitoring, and rapid credential and session revocation capabilities. Organizations also need visibility beyond their traditional endpoints and domains, because attackers can compromise a trusted external platform and weaponize the organization’s brand without ever breaching the corporate network itself.
For users, there should also be a very simple rule: a website, advertisement, CAPTCHA, or software installer should almost never require you to manually paste an unfamiliar command into PowerShell or Terminal. That behavior should immediately be treated as a potential compromise attempt.”
This is an illustration of think before you click. Because threat actors are counting on the fact that you won’t do that and get pwned as a result.
Related
This entry was posted on September 14, 2026 at 5:11 pm and is filed under Commentary with tags Hacked, HBO. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers compromised HBO Max’s official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. Security researchers at Hudson Rock and ADAMnetworks analyzed the campaign and say the verified u/hbomax Reddit account was hijacked and used to launch 108 malicious advertisements over about 48 hours.
Commenting on this is Ensar Seker, CISO at SOCRadar:
“This incident demonstrates how attackers are increasingly weaponizing trust rather than relying purely on technical exploitation. A malicious advertisement coming from a random account immediately raises suspicion, but an advertisement associated with a verified HBO Max account carries an implicit level of legitimacy. Once attackers compromise a trusted brand identity, they effectively inherit that trust and can use it as part of the social-engineering attack chain.
ClickFix is particularly effective because the attacker convinces the victim to execute the malicious action themselves. Instead of delivering a conventional executable that security controls may block, the victim is instructed to copy and paste commands into PowerShell, Windows Run, or macOS Terminal. From a detection perspective, this is challenging because legitimate operating-system tools are being used, and the initial execution is performed by the user. In this campaign, researchers observed payloads ranging from information stealers to cryptocurrency theft tools, with targeting across both Windows and macOS.
The larger security lesson is that organizations must treat corporate social-media and advertising accounts as privileged infrastructure. These accounts should have phishing-resistant MFA, tightly controlled administrator access, continuous monitoring, and rapid credential and session revocation capabilities. Organizations also need visibility beyond their traditional endpoints and domains, because attackers can compromise a trusted external platform and weaponize the organization’s brand without ever breaching the corporate network itself.
For users, there should also be a very simple rule: a website, advertisement, CAPTCHA, or software installer should almost never require you to manually paste an unfamiliar command into PowerShell or Terminal. That behavior should immediately be treated as a potential compromise attempt.”
This is an illustration of think before you click. Because threat actors are counting on the fact that you won’t do that and get pwned as a result.
Share this:
Like this:
Related
This entry was posted on September 14, 2026 at 5:11 pm and is filed under Commentary with tags Hacked, HBO. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.