You might often find yourself hesitant when a strange pop-up or an unknown website asks you to download something. But what if the ad is from a legitimate company? That situation is precisely what makes a recent malware campaign involving HBO Max rather alarming.
Researchers from Hudson Rock discovered that cybercriminals took control of HBO Max’s verified Reddit account, using it to push out 108 different malicious ads over a two-day period. These ads promoted downloads for HBO Max, as well as artificial intelligence tools, developer software, and utilities for Mac. The fact that they appeared under a verified corporate account meant that potential victims had fewer reasons to be skeptical.
It’s worth noting that you don’t need to be an HBO Max user to fall victim to this type of attack. The key takeaway here is the way that criminals can exploit the credibility of verified accounts to disarm your caution. Once you click on such an ad, the attack can unfold quite unexpectedly.
The HBO Max ad appeared more legitimate than typical scams
The issue first came to light when a Reddit user noticed an ad posted by the verified account u/hbomax. This ad seemed to promote a legitimate HBO Max app for macOS—a service HBO Max doesn’t currently support. Users are directed to stream via their browser instead. Following the ad brought them to a convincing landing page. However, the download button didn’t behave as expected; instead of downloading a file, the website prompted users to copy a command and paste it into their Terminal. That should immediately raise suspicions. For Windows users, there were various pathways for attack through Run and PowerShell commands. Researchers noted that some methods could directly load malware into memory.
ClickFix tricks users into running malware themselves
The technique used in this campaign is called ClickFix. Rather than relying solely on a harmful download, ClickFix provides instructions that lead victims to execute the attack themselves. The prompt may claim that a CAPTCHA failed. Alternatively, it could suggest fixing a perceived browser issue or completing an installation. A malicious webpage could even place a command onto your clipboard, instructing you on where to paste it. This could easily seem like regular troubleshooting, especially when the page looks professional and comes from a trusted account. In the HBO Max case, this approach aimed to get victims to run attacker-supplied code through Terminal, bypassing some security measures designed to prevent malicious downloads. A simple warning to remember: no legitimate website should ask you to paste an unfamiliar command into your Terminal or PowerShell to confirm you are human or install consumer software.
The HBO Max account pushed a staggering 108 malicious ads
The fraudulent HBO Max download was just part of what was uncovered. Hudson Rock reported that attackers utilized the compromised Reddit account to circulate 108 distinct ads during the campaign. The ads transitioned between various software lures as domains were taken down or abandoned. The researchers identified:
- 40 ads linked to an HBO Max-themed domain
- 36 ads for an AI and developer lure
- 15 ads tied to a Mac system utility
- 11 ads promoting another developer tool
- 6 ads related to an HBO Max Mac lure
This rapid switching illustrates how attackers can recycle the credibility of a compromised account while altering the websites and software presented to victims.
Researchers associate the ads with a broader operation
Hudson Rock and ADAMnetworks linked the HBO Max campaign to a wider operation named PasteSwitch. This term highlights that the technique revolves around victims pasting commands provided by the attackers, while the rest of the delivery system varies based on the visitor and the campaign.
This means that two individuals clicking similar malicious ads might not receive the same malware. For Mac users, researchers found several payload pathways within PasteSwitch. Methods like MacSync could steal various types of secure information, including browser and Apple Notes data. They also documented an AMOS helper chain designed to maintain access to infected devices.
Another aspect of this operation involved fake versions of cryptocurrency wallet apps like Ledger and Exodus, designed to capture critical recovery phrases. A single wrong command could expose much more than just the webpage you were on.
Windows users faced different malware paths
The PasteSwitch operation could recognize Windows users and adapt its attack accordingly. One method involved a route that used mshta and PowerShell to deliver a malicious file disguised as an MP3/HTA file, later creating a scheduled task to run PowerShell.
Further stages could inject malware directly into memory, making it particularly stealthy. Researchers also uncovered techniques that disguised malicious traffic to appear as though it was communicating with Facebook, complicating basic network monitoring. The fundamental attack revolves around convincing someone to paste a command.
PasteSwitch can tamper with cryptocurrency wallet addresses
Researchers also linked PasteSwitch to another dangerous tool known as clipboard hijackers. These introduced malware called AnimateClipper and ZigClipper, which can monitor clipboard activities and replace cryptocurrency addresses during transactions.
This means a user might copy the correct wallet address, paste it into a transaction, and unwittingly send funds to the wrong place. Researchers saw significant traffic changes made by the same attacker-controlled address between March and July 2026, allowing the operation to remain agile.
Why verified accounts can mislead even careful individuals
Most people tend to trust recognizable names online. A familiar brand coupled with a verification badge often convinces users that the associated ad is safe. However, verified accounts can still be compromised.
According to Hudson Rock, attackers capitalized on HBO Max’s trusted advertisement identity during this campaign, allowing less skepticism from users. This highlights a crucial point about how we assess online advertisements.
If you see an ad for software you’re interested in, it’s wise to open a new tab and visit the company’s official website instead of clicking the ad. Those extra moments could save you from a potential attack.
Reddit has confirmed the account was compromised
Reddit has acknowledged that an HBO Max account authorized to run ads on their platform was compromised and used for distributing malicious links. In a statement, Reddit mentioned they locked the account, removed the ads, and are collaborating with HBO Max to enhance account security. They haven’t observed any impacts on other advertising accounts.
Attempts to contact HBO Max for a response went unanswered before the deadline.
ClickFix has emerged as a key malware delivery method
ClickFix has gained traction because attackers manage to persuade victims to execute the harmful action themselves. One report noted that ClickFix constituted 53% of the malware loader activity observed in 2025. Attackers also continuously adapt their tactics.
We’ve seen fake CAPTCHA forms propagate through numerous compromised websites, and counterfeit Windows updates utilize similar techniques. Compromised sites may also display bogus verification prompts aimed at steering visitors toward harmful commands. The presentation may vary, but the request for you to run an unfamiliar command remains a critical behavior to monitor.
Your Mac might alert you, but don’t rely solely on it
Apple has introduced additional protections against certain ClickFix attacks. On newer macOS versions, Terminal may warn you if pasted text appears to be a harmful command. That warning could help, but users might not always receive prompts for every malicious command. Attackers are constantly refining their strategies, so you must rely on your judgment as well.
Eight ways to safeguard against malicious ads and ClickFix attacks
It’s easy to get drawn in by a convincing advertisement. Following these steps can help you spot warning signs before a single bad click spirals into something bigger.
1) Be cautious with ads, even from verified accounts
A recognizable logo or a verified badge doesn’t guarantee the individual controlling the account is the rightful owner. Whenever possible, visit the official website directly rather than clicking on an ad.
2) Avoid pasting unfamiliar commands
If a page instructs you to open Terminal, PowerShell, or the Run dialog to paste something, close it immediately. Legitimate consumer software typically doesn’t require you to manually run unknown commands.
3) Obtain software from official sources
Always use the developer’s official website or your device’s app store. Stay particularly cautious if an ad suddenly offers software you’ve never heard of.
4) Watch for clipboard interactions
Some ClickFix pages might copy harmful text into your clipboard. If your security software alerts you about unexpected clipboard activities, take it seriously.
5) Keep your device and browser up to date
Security updates can provide protection against evolving attack methods. Install these updates through your system settings or the software’s built-in updater.
6) Use strong antivirus software with real-time protection
Robust antivirus programs can block harmful websites and detect malware if it slips past your browser, offering an extra layer of defense.
7) Act swiftly if you’ve executed a suspicious command
Disconnect from the internet immediately and run a thorough scan using trusted antivirus software. From a clean device, change passwords for sensitive accounts starting with your primary email. Then check financial accounts and cryptocurrency wallets for unfamiliar activity.
8) Enable multifactor authentication
An info-stealer might capture passwords and browser data. Multifactor authentication can hinder the usability of stolen credentials, although some malware can bypass standard protections.
Key takeaways
This incident really highlights how quickly something that seems risky can start to feel legitimate. The ad originated from a verified corporate account, the landing page looked polished, and the instructions felt like typical installation steps. This blend can defeat the skepticism many of us have developed towards clearly shady scams. My suggestion? Focus less on how professional an ad appears and more on its requests. The moment a site instructs you to open Terminal or paste a command, stop right there. Cybercriminals will continually seek to exploit the reputations of trusted companies. We need to adjust our instincts as these attacks evolve.
Would you still trust an online ad just because it comes from a verified company account, or has this changed how you evaluate safety online? Let us know your thoughts.






