Meyka Pro banner
Global Market Insights

ClickFix Malware Hits Reddit Via Hacked HBO Max Account on September 20

September 21, 2026
02:41 AM
4 min read

Key Points

Hackers compromised HBO Max's Reddit account and posted 108 malicious ads over 48 hours.

The ClickFix attack tricks users into pasting terminal commands that instantly install info-stealing malware.

The malware captures passwords, account access, and cryptocurrency wallets before antivirus tools can detect it.

Warner Bros. Discovery has not disclosed how the account was hacked or responded to the breach.

Be the first to rate this article

Attackers compromised HBO Max’s verified Reddit account and launched a 48-hour malvertising blitz that pushed 108 malicious ads targeting Windows and Mac users. The ClickFix campaign, dubbed PasteSwitch, tricked victims into copying and pasting commands into their terminal, instantly installing info-stealing malware. Security researchers at Hudson Rock and ADAMnetworks confirmed the attack on September 6, and Reddit paused the ads three days later.

How the ClickFix attack worked

The fake ads on Reddit appeared to promote an HBO Max macOS app, which the streaming service does not actually offer. Clicking the ad sent users to a lookalike landing page (hbomaxx[.]us) with a download button. Instead of downloading, the button displayed instructions telling users to copy and paste a command string into Terminal on macOS or Command Prompt on Windows. Once executed, the malware installed instantly, bypassing antivirus defenses because it ran at the operating system level.

What the malware steals

The info-stealing payload immediately captures passwords, access to logged-in accounts, and cryptocurrency wallets. Security researchers tested the attack in a sandboxed environment without running the executable. The malware can also collect system details including architecture, hostname, CPU, memory, and uptime, then exfiltrate the data through hardcoded Slack and Telegram channels.

The scope of the campaign

Researchers at Hudson Rock and ADAMnetworks analyzed the ads and found the HBO Max account hijacking was part of a massive malvertising blitz. Of the 108 distinct ads pushed during the 48-hour window, fewer than half advertised HBO Max lures. Another 47 ads targeted developers with fake AI programming tools, and 15 promoted a macOS disk cleaner. It remains unclear how many people clicked on the fake ads or were ultimately compromised. Warner Bros. Discovery, HBO Max’s parent company, did not respond to requests for comment.

Why ClickFix attacks are rising in 2026

ClickFix attacks have evolved from rare exploits targeting people searching for tech fixes into a massive international effort. The attacks exploit human psychology: CAPTCHAs are annoying by design, so users comply without thinking. The terminal-based execution bypasses traditional security tools because it operates at the operating system level, making detection harder than malware installed through normal application channels.

Final Thoughts

The HBO Max breach shows how attackers exploit trusted brand accounts and user psychology to distribute malware at scale. For Canadian users, the lesson is clear: never copy and paste terminal commands from unknown sources, even if they appear to come from verified accounts. Verify any unusual requests directly with the company.

FAQs

How did hackers get access to HBO Max’s Reddit account?

The research context does not specify how the account was compromised. Warner Bros. Discovery has not disclosed the method or whether the attacker used stolen credentials or another vulnerability.

What should I do if I clicked the fake HBO Max ad on Reddit?

If you did not paste a command into Terminal or Command Prompt, your device is safe. If you did run the command, immediately change all passwords, check for unauthorized account access, and scan your system with antivirus software.

Why does copying a terminal command install malware?

Terminal commands execute at the operating system level with full system privileges. This bypasses antivirus defenses because the malware runs before security tools can detect it, giving it immediate access to passwords and files.

How many people were infected by the ClickFix attack?

The exact number of victims is unknown. Reddit paused the ads after 108 malicious ads were posted, but security researchers have not disclosed how many users clicked or were compromised.

Disclaimer:

The content shared by Meyka AI PTY LTD is solely for research and informational purposes.  Meyka is not a financial advisory service, and the information provided should not be considered investment or trading advice.

About Author

Author

Danny Kontos

Co Founder

Danny Kontos has been a stock investor since 2007 and co-founded Meyka in 2023. He keeps a small, focused portfolio and only moves when the numbers are hard to argue with. He has waited years on a single position before. Before Meyka, he ran a web hosting company and a mortgage lending platform, so he knows what a well-run business actually looks like under the hood. This article did not come from a news cycle. It came from someone who has been watching this space for a long time.

What brings you to Meyka?

Pick what interests you most and we will get you started.

I'm here to read news

Find more articles like this one

I'm here to research stocks

Ask Meyka Analyst about any stock

I'm here to track my Portfolio

Get daily updates and alerts (coming March 2026)