Attackers hijacked the verified HBO Max Reddit account and deployed it to distribute more than 100 malicious advertisements serving infostealer malware targeting both Windows and macOS devices, according to a report published by Hudson Rock and ADAMnetworks analyzing the September 2026 attack. Security researchers who examined the incident dubbed it PasteSwitch and characterized it as a "massive 48-hour malvertising blitz" using ClickFix social engineering tactics. The streaming platform's compromised account pushed fraudulent ads for a macOS HBO Max app — a product that doesn't actually exist, since the service offers no native Mac client.
The campaign deployed 108 distinct advertisements across multiple software themes between September 6 and when Reddit paused the malicious activity three days later. Of these, 46 ads used HBO Max as the lure, directing targets to fraudulent domains including hbomaxx[.]app or hbomax-macos[.]com. Another 36 advertisements impersonated OpenAI Codex, routing victims to codex-craft[.]com, while 15 posed as a macOS disk utility pointing to apple.clean-disk-guide[.]com. The remaining 11 used other developer tools as bait, sending clicks to code-desktop[.]com. The attack delivered multiple malware types depending on the victim's operating system, including infostealers, malware loaders, cryptocurrency clippers called AnimateClipper and ZigClipper, and counterfeit cryptocurrency wallet applications.
Hudson Rock co-founder and CTO Alon Gal stated that "the campaign proves once again why trusted distribution channels are becoming prime targets for infostealer delivery." A Reddit user who discovered the attack on September 6 noted the advertisement displayed u/hbomax as the author — the verified HBO Max account — and described the command-paste technique as "the classic infostealer/clickfix paste this command to download." The researchers observed that the cryptocurrency clippers use Binance Smart Chain contracts to dynamically retrieve whatever command-and-control domain the attackers are currently operating, with Hudson Rock noting that between March and July 2026, they witnessed 36 mainnet changes executed by the same attacker controller address.
The attack exploited ClickFix tactics, a social engineering method where victims are tricked into copying and pasting malicious commands into their system terminal. When users clicked on the fraudulent HBO Max ad, they landed on a somewhat-legitimate-appearing page featuring a join or download button. Pressing that button generated instructions directing Mac users to copy and paste a command into Terminal, which would then execute the malware payload. The report emphasizes that because the command-and-control domain is hosted directly on the blockchain, the infrastructure shows dynamic resilience, letting threat actors easily rotate compromised domains without losing operational control. This blockchain-based fallback mechanism makes takedown efforts significantly more challenging for defenders.
The incident demonstrates that criminals continue making heavy use of ClickFix attacks with little indication this social engineering approach will disappear soon. Warner Bros. Discovery, HBO Max's parent company, did not immediately respond to inquiries about the account takeover, including who hijacked the streaming service's Reddit account and how they accomplished it. Reddit's safety and security teams launched an investigation after pausing the infostealer-dropping advertisements three days into the campaign. The rise of account takeovers on trusted platforms forces security teams to rethink how they authenticate even verified corporate social media presence, particularly as attackers refine methods that blur the line between legitimate software distribution and malware delivery.

