HBO Max Reddit account compromised to serve ClickFix attacks
- ID
- 24455
- Status
- summarized
- Published
- 15 Sep 2026, 6:43 AM
- Fetched
- 15 Sep 2026, 8:58 AM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 5.5
- Created
- 15 Sep 2026, 9:02 AM
- Tags
- Audience
- developerssaas_founders
What happened
Attackers compromised HBO Max's verified Reddit account (u/hbomax) to push 108 malicious ads over 48 hours in a campaign dubbed PasteSwitch, targeting both macOS and Windows users with infostealers, malware loaders, crypto clippers, and fake wallet apps. The ads used a fake HBO Max macOS app lure — no native Mac client exists — directing victims to paste a command into Terminal, the classic ClickFix pattern.
Why it matters
If you manage any brand-owned social account, this shows a verified badge is not a trust signal for your users — it's an attack surface. Review who has admin access to your company's Reddit, X, and other social accounts, and enable hardware-key 2FA. The ClickFix 'paste this command into Terminal' pattern is now being delivered through high-trust channels, so any download instructions your product publishes should be clearly authenticated and users should be warned about paste-to-terminal social engineering.
Discussion angle
How would your team respond if a verified brand social account started serving malware — do you have an incident runbook for social account compromise, and would you even detect it before a user on Reddit does?