TechNewsReel
Live

Hackers Hijack Verified HBO Max Reddit Account to Deploy 'ClickFix' Malware

Attackers used a compromised corporate account to trick users into manually executing info-stealing code via their system terminals.

TechNewsReel Newsroom · September 15, 2026

Cybercriminals compromised the official, verified HBO Max Reddit account in September 2026 to launch a high-velocity malvertising campaign. The breach allowed attackers to weaponize a trusted corporate identity to bypass user skepticism and deploy info-stealing malware.

Over a 48-hour window, the hijacked account (u/hbomax) pushed 108 malicious advertisements. These ads directed users to fraudulent HBO Max landing pages that employed a social engineering tactic known as "ClickFix." Once on these pages, both Windows and macOS users were tricked into copying and pasting malicious commands directly into their system terminals or command prompts. Reddit locked the account and removed the ads after learning that an authorized account had been compromised to run links containing malware.

The Rise of ClickFix

ClickFix represents a growing trend in 2026 social engineering. Rather than relying on traditional file downloads that might be flagged by security software, attackers use fake CAPTCHAs or simulated "technical error" popups. These prompts convince the user that they must manually run a specific command to "fix" the page or verify their identity. Because the user initiates the command, the malware often bypasses traditional antivirus tools by leveraging the user's own administrative privileges to execute the payload.

Industry Implications

This specific campaign is part of a larger cross-platform operation dubbed "PasteSwitch" by researchers from Hudson Rock and ADAMnetworks. The primary objective of the malware was the theft of sensitive data, including saved passwords, session cookies, and cryptocurrency wallets.

The incident highlights a critical vulnerability in the trust model of verified social media accounts. When a verified corporate entity is compromised, the inherent trust users place in the "check mark" becomes a delivery mechanism for attacks. By targeting the system terminal directly, the PasteSwitch operation demonstrated how easily users can be manipulated into "hacking themselves," turning the OS's most powerful tools into liabilities.

What to Watch

Security experts are now monitoring for further iterations of the PasteSwitch operation as attackers refine their social engineering scripts. While Reddit has mitigated this specific breach, the success of the ClickFix method suggests a shift toward "human-assisted" malware installation. Users are advised to never copy and paste commands into a terminal from an external website, regardless of the perceived urgency or the verification status of the source.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.