TechNewsReel
Live

Hackers Use Compromised HBO Max Reddit Ads to Trick Users Into Installing Malware

A sophisticated 'ClickFix' campaign leverages official advertising accounts to bypass security by tricking victims into manually executing malicious code.

TechNewsReel Newsroom · September 14, 2026

Cybercriminals recently compromised an official HBO Max advertising account on Reddit to launch a deceptive 'ClickFix' malware campaign. The attack represents a dangerous shift in social engineering, turning users into the primary vector of their own system compromise.

According to reports from TechCrunch, users who clicked the malicious ads were redirected to fraudulent HBO Max pages. These sites mimicked standard CAPTCHAs or anti-bot verification checks to create a sense of legitimacy. To proceed, victims were instructed to copy and paste specific commands into the Windows Command Prompt or macOS Terminal. Once executed, these commands instantly installed info-stealing malware on the device.

The Mechanics of ClickFix

This incident is part of a broader 'ClickFix' trend. In these scenarios, attackers lure users into 'fixing' a perceived technical error—such as a browser crash or a failed security check—by running a provided command.

This 'Paste-and-Run' method is particularly effective because it utilizes trusted system tools like PowerShell or Terminal to execute the payload. Because the user is manually entering the command rather than downloading a suspicious file, the attack often evades traditional endpoint security and antivirus software that typically monitor file-based downloads but not manual terminal input.

High-Stakes Data Theft

The malware deployed in this campaign is specifically designed for high-value data exfiltration. Once the system is compromised, the software targets stored passwords, active logged-in account sessions, and cryptocurrency wallets. By targeting both Windows and macOS users, the attackers have cast a wide net across the two most common desktop operating systems.

Why This Shift Matters

This campaign demonstrates a sophisticated evolution in delivery methods. Rather than relying on generic phishing emails that are often flagged by spam filters, hackers are now compromising high-trust, official advertising accounts on major platforms like Reddit.

By leveraging the inherent trust users place in official brand advertisements, attackers can bypass the initial 'security wall' of the browser. When combined with the manual execution of code, the attack effectively neutralizes many of the automated defenses built into modern operating systems.

Current Status and Outlook

Reddit has since confirmed that an authorized HBO Max account was compromised and used to distribute the malicious links. A Reddit spokesperson stated that the platform has locked the affected account and removed the fraudulent advertisements.

Security experts continue to monitor the spread of ClickFix tactics. While the HBO Max ads have been neutralized, the success of the 'Paste-and-Run' method suggests that other high-trust platforms may be targeted. Users are urged to never copy and paste commands into a terminal from an untrusted web source, regardless of how legitimate the site appears.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.