Key Points
Hackers compromised HBO Max's Reddit account and posted 108 malicious ads over 48 hours.
The ClickFix attack tricks users into pasting terminal commands that instantly install info-stealing malware.
The malware captures passwords, account access, and cryptocurrency wallets before antivirus tools can detect it.
Warner Bros. Discovery has not disclosed how the account was hacked or responded to the breach.
Attackers compromised HBO Max’s verified Reddit account and launched a 48-hour malvertising blitz that pushed 108 malicious ads targeting Windows and Mac users. The ClickFix campaign, dubbed PasteSwitch, tricked victims into copying and pasting commands into their terminal, instantly installing info-stealing malware. Security researchers at Hudson Rock and ADAMnetworks confirmed the attack on September 6, and Reddit paused the ads three days later.
How the ClickFix attack worked
The fake ads on Reddit appeared to promote an HBO Max macOS app, which the streaming service does not actually offer. Clicking the ad sent users to a lookalike landing page (hbomaxx[.]us) with a download button. Instead of downloading, the button displayed instructions telling users to copy and paste a command string into Terminal on macOS or Command Prompt on Windows. Once executed, the malware installed instantly, bypassing antivirus defenses because it ran at the operating system level.
What the malware steals
The info-stealing payload immediately captures passwords, access to logged-in accounts, and cryptocurrency wallets. Security researchers tested the attack in a sandboxed environment without running the executable. The malware can also collect system details including architecture, hostname, CPU, memory, and uptime, then exfiltrate the data through hardcoded Slack and Telegram channels.
The scope of the campaign
Researchers at Hudson Rock and ADAMnetworks analyzed the ads and found the HBO Max account hijacking was part of a massive malvertising blitz. Of the 108 distinct ads pushed during the 48-hour window, fewer than half advertised HBO Max lures. Another 47 ads targeted developers with fake AI programming tools, and 15 promoted a macOS disk cleaner. It remains unclear how many people clicked on the fake ads or were ultimately compromised. Warner Bros. Discovery, HBO Max’s parent company, did not respond to requests for comment.
Why ClickFix attacks are rising in 2026
ClickFix attacks have evolved from rare exploits targeting people searching for tech fixes into a massive international effort. The attacks exploit human psychology: CAPTCHAs are annoying by design, so users comply without thinking. The terminal-based execution bypasses traditional security tools because it operates at the operating system level, making detection harder than malware installed through normal application channels.
Final Thoughts
The HBO Max breach shows how attackers exploit trusted brand accounts and user psychology to distribute malware at scale. For Canadian users, the lesson is clear: never copy and paste terminal commands from unknown sources, even if they appear to come from verified accounts. Verify any unusual requests directly with the company.
FAQs
The research context does not specify how the account was compromised. Warner Bros. Discovery has not disclosed the method or whether the attacker used stolen credentials or another vulnerability.
If you did not paste a command into Terminal or Command Prompt, your device is safe. If you did run the command, immediately change all passwords, check for unauthorized account access, and scan your system with antivirus software.
Terminal commands execute at the operating system level with full system privileges. This bypasses antivirus defenses because the malware runs before security tools can detect it, giving it immediate access to passwords and files.
The exact number of victims is unknown. Reddit paused the ads after 108 malicious ads were posted, but security researchers have not disclosed how many users clicked or were compromised.
Disclaimer:
The content shared by Meyka AI PTY LTD is solely for research and informational purposes. Meyka is not a financial advisory service, and the information provided should not be considered investment or trading advice.
About Author

Danny Kontos
Co FounderDanny Kontos has been a stock investor since 2007 and co-founded Meyka in 2023. He keeps a small, focused portfolio and only moves when the numbers are hard to argue with. He has waited years on a single position before. Before Meyka, he ran a web hosting company and a mortgage lending platform, so he knows what a well-run business actually looks like under the hood. This article did not come from a news cycle. It came from someone who has been watching this space for a long time.
What brings you to Meyka?
Pick what interests you most and we will get you started.
I'm here to read news
Find more articles like this one
I'm here to research stocks
Ask Meyka Analyst about any stock
I'm here to track my Portfolio
Get daily updates and alerts (coming March 2026)