Compromised HBO Max Reddit account used to spread info-stealing malware via fake ads

Attackers took over the verified HBO Max Reddit account and ran over a hundred malicious advertisements over two days. The ads used ClickFix social engineering to trick users into running commands that install information-stealing malware on Windows and macOS. Researchers link this to a broader campaign called PasteSwitch that also targets cryptocurrency wallets.
The hijacked account posted 108 ads over roughly two days, impersonating not just HBO Max but also fake AI tools and developer utilities. The ClickFix method relies on victims pasting commands themselves, which can bypass browser-based malware detection. Researchers tied the operation to PasteSwitch, a broader campaign that also targets cryptocurrency users with clippers and fake wallet apps. On macOS, one payload called MacSync steals browser credentials, Telegram data, and Apple Notes, while another establishes persistence through a hidden directory to receive further instructions from attacker servers.
This incident shows how verified accounts on major platforms can be weaponized to distribute malware, potentially eroding trust in official channels. Users who clicked the ads may have exposed passwords, financial data, or cryptocurrency holdings. The ClickFix technique could bypass some security tools, meaning even cautious users might be at risk. Broader adoption of such social engineering may increase, affecting both individuals and organizations that rely on platform verification as a safety signal.