Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
HBO Max’s Reddit Hacked for Malware Distribution

HBO Max’s Reddit Hacked for Malware Distribution

Posted on September 15, 2026 By CWS

The official HBO Max account on Reddit was recently compromised by cybercriminals who leveraged it for a malvertising campaign. This attack, identified as PasteSwitch, saw the hackers deploying malicious ads that directed users to a deceptive webpage.

Pasting Malicious Ads

Over a 48-hour span, the attackers launched 108 harmful advertisements across five distinct groups. These ads were strategically designed to lure both macOS and Windows users by promoting a fictitious HBO Max application for macOS.

Upon clicking these ads, users were redirected to a counterfeit site, hbomaxx[.]us, which closely resembled the legitimate HBO Max website. This page included a download button purporting to offer the non-existent app.

Malware Delivery Mechanisms

The malicious download button initiated a ClickFix prompt, instructing users to execute a command in Terminal, thereby transferring control from the web browser to the user’s system. This method was particularly aimed at macOS users, using curl | zsh commands to install malware such as MacSync and AMOS Helper.

For Windows users, the attack employed MSHTA and PowerShell scripts to deploy the Amatera Stealer malware, which could evade detection by mimicking Facebook connections to conceal its command-and-control operations.

Persistent Threats and Response

The PasteSwitch campaign also utilized AnimateClipper and ZigClipper tools to replace clipboard content, specifically targeting cryptocurrency transactions. These tools were managed through a command-and-control system hosted on the blockchain, which has been active since early 2026.

Upon discovery of these activities, Reddit was alerted and swiftly suspended the malicious advertisements linked to the HBO Max account.

SecurityWeek has reached out to Warner Bros., the parent company of HBO Max, for an official statement regarding the breach. Further updates will be provided as new information becomes available.

Security Week News Tags:attack campaign, ClickFix, Clickjacking, Cryptocurrency, Cybersecurity, Hacking, HBO Max, macOS, malicious ads, Malvertising, Malware, PasteSwitch, Reddit, security threats, Windows

Post navigation

Previous Post: Leading Serverless Security Solutions for 2026
Next Post: Leading Kubernetes Security Tools for 2026

Related Posts

ManoMano Data Breach Affects 38 Million Users ManoMano Data Breach Affects 38 Million Users Security Week News
US Federal Agency Hit by Firestarter Backdoor in Cisco Firewalls US Federal Agency Hit by Firestarter Backdoor in Cisco Firewalls Security Week News
GitLab, Atlassian Patch High-Severity Vulnerabilities GitLab, Atlassian Patch High-Severity Vulnerabilities Security Week News
CISA Calls to Fix Critical Microsoft, VMware, Apple Flaws CISA Calls to Fix Critical Microsoft, VMware, Apple Flaws Security Week News
Penn and Phoenix Universities Disclose Data Breach After Oracle Hack Penn and Phoenix Universities Disclose Data Breach After Oracle Hack Security Week News
Daylight Raises  Million for AI-Powered MDR Platform Daylight Raises $33 Million for AI-Powered MDR Platform Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Major Vulnerabilities Found in WordPress Plugin
  • Microsoft Sets AI Cybersecurity Boundaries in New Code
  • Leading Kubernetes Security Tools for 2026
  • HBO Max’s Reddit Hacked for Malware Distribution
  • Leading Serverless Security Solutions for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Major Vulnerabilities Found in WordPress Plugin
  • Microsoft Sets AI Cybersecurity Boundaries in New Code
  • Leading Kubernetes Security Tools for 2026
  • HBO Max’s Reddit Hacked for Malware Distribution
  • Leading Serverless Security Solutions for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark