MalwareTips News Hijacked HBO Max Reddit account pushed command-based malware ads

How often do you download software after seeing it in an online ad?

  • Never

    Votes: 4 80.0%
  • Rarely

    Votes: 0 0.0%
  • Sometimes

    Votes: 0 0.0%
  • Often

    Votes: 0 0.0%
  • I am not sure

    Votes: 1 20.0%

  • Total voters
    5

News Now

Happening Now
Thread author
Verified
Sep 8, 2026
24
59
1
Cybercriminals hijacked HBO Max’s verified Reddit account and used it to publish 108 malicious ads in about 48 hours, according to researchers. Anyone who followed those ads and pasted a suggested command into Terminal, PowerShell or Windows Run may have exposed passwords, browser data or cryptocurrency wallets.

Trusted account, unsafe ads​

Malwarebytes Labs reported that the ads promoted fake AI tools, developer software and Mac utilities through HBO Max’s corporate account. Some led to convincing HBO lookalike sites offering a supposed native HBO Max app for macOS or another promotional download.

Reddit paused the ads and opened a security investigation after receiving reports.


The download was really a ClickFix trap​

Instead of supplying an installer, the sites told visitors to paste a command into macOS Terminal, or into the Run dialog or PowerShell on Windows. This method is known as ClickFix: a page presents malicious commands as a normal installation, CAPTCHA or troubleshooting step, sometimes copying the command to the clipboard first.

ADAMnetworks named the operation behind these ads “PasteSwitch” and found that its next stage appeared to change according to the visitor’s device and the lure shown.

What could be stolen​

Observed Mac payloads included the MacSync and AMOS information stealers. They target browser credentials and profiles, Telegram data, Apple Notes, saved passwords and cryptocurrency wallet recovery phrases.

Windows visitors could receive the memory-based Amatera information stealer. The campaign was also linked to clipboard hijackers that replace a copied cryptocurrency wallet address with one controlled by an attacker.

Steps to avoid this attack​

  • Open a company’s official website yourself rather than installing software through a social media ad.
  • Do not paste commands from ads, websites, emails or messages unless you trust the source and understand exactly what they do.
  • Ignore countdowns and other pressure tactics. Verify unusual instructions through official documentation or the company’s support team.
  • Keep real-time anti-malware and web protection enabled and up to date. Malwarebytes identifies ember-bridge.com as part of the PasteSwitch infrastructure.
 

You may also like...