Compromised HBO Max ad account spread ClickFix malware on Reddit
Attackers abused an HBO Max account authorized to publish ads on Reddit. The malicious campaigns prompted users to run a malware-laden command themselves on Windows or macOS.

HBO Max ClickFix malware spread through a compromised advertising account on Reddit. The platform confirmed to TechCrunch that an account authorized to run ads had been abused to publish ads containing malicious links. Reddit locked the account and removed the ads.
Researchers from Hudson Rock and ADAMnetworks documented 108 malicious ads from the verified u/hbomax account. The campaign ran for approximately 48 hours, on September 13 and 14, 2026. It is not known how many users clicked the ads, followed the displayed instructions, or had a compromised device.
HBO Max ClickFix malware required user action
The ads directed users to fake websites imitating HBO Max and other brands. They used the ClickFix technique, in which a site persuades the victim to copy and run a command. In this case, the command may have been entered into Terminal on macOS, or into PowerShell or the Run dialog on Windows.
Automatic infection after viewing the ad was not confirmed. The key step was the user manually executing the malicious command. This approach shifts code execution directly to the victim and may bypass some standard security checks associated with downloading files.
ADAMnetworks analyzed the macOS branch of the campaign and said the malware stole data from browsers, the system Keychain, crypto wallets, and other information. The analysis also detected persistence mechanisms, meaning procedures intended to maintain access to the system. The researchers named the operation PasteSwitch.
A trusted advertising account gave the campaign legitimacy
The case is particularly significant because of the distribution method. The malicious ads were published from the verified u/hbomax account, which was authorized to run ads. Users could therefore perceive the malicious content as legitimate paid promotion.
The risk primarily concerns people who, after clicking an ad, followed instructions on the fake site and entered a command into Terminal, PowerShell, or the Run window. Based on the available findings, clicking alone is not a confirmed infection mechanism.
With similar prompts, a website should not require users to run a command in a system interface to supposedly verify their identity, play content, or fix an error. Such a request is a reason to close the site and not run the command.
The extent of the compromise is not yet known
It has not been confirmed how the attackers gained access to the HBO Max advertising account. It has likewise not been confirmed whether other accounts or the internal systems of Warner Bros. Discovery or HBO were affected. The available information also does not state how many users were affected.
Further developments may bring a statement from Warner Bros. Discovery or HBO Max regarding the scope of the incident and the method of compromise. Potential Reddit data on the ads’ reach, new indicators of compromise, and PasteSwitch malware removal tools for affected devices will also be important.
Sources
- Reddit (statement relayed by TechCrunch) – Reddit confirmed the compromise of an account authorized to run ads, its lockout, and the removal of the malicious ads.
- ADAMnetworks – Original technical analysis of the PasteSwitch campaign, the 108 ads, lure domains, the ClickFix mechanism, and the analyzed malicious payloads.
- BleepingComputer – Independent summary of the incident, the researchers’ technical findings, and the information that the method of access and the further scope had not been confirmed.
Verified and updated: September 15, 2026 06:24



