VYPR
advisoryPublished Sep 14, 2026· 1 source

HBO Max Reddit Account Hijacked for Widespread Malvertising Campaign

The official HBO Max Reddit account was compromised to distribute over 100 malicious ads pushing ClickFix attacks with information-stealing malware for Windows and macOS.

The official Reddit account for HBO Max was hijacked and used in a significant malvertising campaign that pushed over 100 malicious ads, ultimately delivering ClickFix attacks laden with information-stealing malware targeting both Windows and macOS users. The compromise was first noticed on September 6th by a Reddit user who observed ads authored by the verified u/hbomax account, promoting a non-existent HBO Max macOS application. Clicking these ads led users to a convincing-looking landing page, hbomaxx[.]us, which prompted them to download an application. This download process involved instructing users to copy and paste commands into their system's Terminal, a classic tactic for delivering infostealers.

Researchers from Hudson Rock and ADAMnetworks analyzed the campaign, which they've named "PasteSwitch." They described it as a "massive 48-hour malvertising blitz" that utilized a variety of lures beyond just HBO Max. The attackers deployed 108 distinct ads, employing themes related to developer tools, disk cleaners, and AI, including fake advertisements for OpenAI Codex. The payloads delivered by PasteSwitch are diverse, encompassing infostealers, malware loaders, cryptocurrency clippers, and fraudulent cryptocurrency wallet applications.

For its command-and-control (C2) infrastructure, the PasteSwitch campaign demonstrated remarkable resilience by leveraging Binance Smart Chain (BSC) contracts. This blockchain-based approach allowed the attackers to dynamically fetch their C2 domains, making it difficult to disrupt their operations by simply blocking known domains. Between March and July 2026, researchers observed 36 mainnet changes executed by the same attacker-controlled address, highlighting the adaptability of this C2 method. By hosting the C2 domain directly on the blockchain, the infrastructure achieved dynamic resilience, enabling threat actors to easily rotate compromised domains.

While 46 of the 108 ads used the HBO Max lure, directing users to domains like hbomaxx[.]app or hbomax-macos[.]com, other lures were also prominent. Thirty-six ads focused on OpenAI Codex, leading to codex-craft[.]com. Additionally, 15 ads promoted fake macOS disk utilities via apple.clean-disk-guide[.]com, and 11 others used developer tool lures, pointing to code-desktop[.]com.

Following the discovery, Reddit temporarily paused the malvertising ads and initiated an investigation. HBO Max's parent company, Warner Bros. Discovery, had not immediately responded to inquiries regarding the account takeover, including details on how the compromise occurred or who was responsible. The incident underscores the growing threat of malvertising and the exploitation of trusted online platforms for malicious purposes.

The PasteSwitch campaign highlights two significant trends in cybercrime: the continued reliance on social engineering tactics like ClickFix attacks, and the increasing sophistication of malvertising operations. The use of a compromised, high-profile Reddit account demonstrates the attackers' strategy of leveraging established trust to reach a wider audience. The campaign's success in delivering varied malware payloads, including cryptocurrency clippers and infostealers, indicates a multi-faceted approach to monetization.

This incident serves as a stark reminder of the importance of verifying the authenticity of online advertisements and software downloads, even when they appear to originate from legitimate sources. The dynamic C2 infrastructure employed by PasteSwitch also points to the evolving tactics threat actors are using to evade detection and maintain operational security, making attribution and takedown efforts increasingly challenging for cybersecurity professionals.

Synthesized by Vypr AI