AI Weekly Malaysia

Back to items Summaries

HBO Max Reddit account compromised to serve ClickFix attacks

ID
24455
Status
summarized
Published
15 Sep 2026, 6:43 AM
Fetched
15 Sep 2026, 8:58 AM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
5.5
Created
15 Sep 2026, 9:02 AM
Tags
Audience
developerssaas_founders

What happened

Attackers compromised HBO Max's verified Reddit account (u/hbomax) to push 108 malicious ads over 48 hours in a campaign dubbed PasteSwitch, targeting both macOS and Windows users with infostealers, malware loaders, crypto clippers, and fake wallet apps. The ads used a fake HBO Max macOS app lure — no native Mac client exists — directing victims to paste a command into Terminal, the classic ClickFix pattern.

Why it matters

If you manage any brand-owned social account, this shows a verified badge is not a trust signal for your users — it's an attack surface. Review who has admin access to your company's Reddit, X, and other social accounts, and enable hardware-key 2FA. The ClickFix 'paste this command into Terminal' pattern is now being delivered through high-trust channels, so any download instructions your product publishes should be clearly authenticated and users should be warned about paste-to-terminal social engineering.

Discussion angle

How would your team respond if a verified brand social account started serving malware — do you have an incident runbook for social account compromise, and would you even detect it before a user on Reddit does?

Top