The official HBO Max account on Reddit was recently compromised by cybercriminals who leveraged it for a malvertising campaign. This attack, identified as PasteSwitch, saw the hackers deploying malicious ads that directed users to a deceptive webpage.
Pasting Malicious Ads
Over a 48-hour span, the attackers launched 108 harmful advertisements across five distinct groups. These ads were strategically designed to lure both macOS and Windows users by promoting a fictitious HBO Max application for macOS.
Upon clicking these ads, users were redirected to a counterfeit site, hbomaxx[.]us, which closely resembled the legitimate HBO Max website. This page included a download button purporting to offer the non-existent app.
Malware Delivery Mechanisms
The malicious download button initiated a ClickFix prompt, instructing users to execute a command in Terminal, thereby transferring control from the web browser to the user’s system. This method was particularly aimed at macOS users, using curl | zsh commands to install malware such as MacSync and AMOS Helper.
For Windows users, the attack employed MSHTA and PowerShell scripts to deploy the Amatera Stealer malware, which could evade detection by mimicking Facebook connections to conceal its command-and-control operations.
Persistent Threats and Response
The PasteSwitch campaign also utilized AnimateClipper and ZigClipper tools to replace clipboard content, specifically targeting cryptocurrency transactions. These tools were managed through a command-and-control system hosted on the blockchain, which has been active since early 2026.
Upon discovery of these activities, Reddit was alerted and swiftly suspended the malicious advertisements linked to the HBO Max account.
SecurityWeek has reached out to Warner Bros., the parent company of HBO Max, for an official statement regarding the breach. Further updates will be provided as new information becomes available.
