Executive Summary
In September 2026, cybercriminals compromised HBO Max's verified Reddit account and launched 108 malicious advertisements over 48 hours, targeting both Windows and macOS users through ClickFix social engineering attacks. The campaign, linked to the broader PasteSwitch operation, tricked victims into executing malicious commands through legitimate system tools like PowerShell and Terminal, bypassing traditional security controls. The attacks distributed information stealers including MacSync and Amatera Stealer, cryptocurrency clippers, and fake wallet applications, demonstrating sophisticated multi-platform targeting capabilities. This incident represents a significant escalation in social media account takeover attacks, where threat actors exploit trusted brand verification to distribute malware at scale. The use of ClickFix techniques shows how attackers are evolving to bypass modern security tools by manipulating users into executing malicious code through legitimate operating system functions.
Why This Matters Now
This attack highlights the growing trend of verified social media account compromises being weaponized for large-scale malware distribution, requiring organizations to reassess their digital brand protection and third-party platform security strategies.
Attack Path Analysis
Attackers compromised HBO Max's Reddit account to post malicious advertisements promoting fake applications. Users were social engineered into executing ClickFix commands that downloaded information stealing malware including MacSync and Amatera Stealer. The malware established persistence, communicated with command and control infrastructure, and exfiltrated browser credentials, cryptocurrency wallets, and system data. The campaign targeted both Windows and macOS users with platform-specific payloads distributed through attacker-controlled domains.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers compromised HBO Max's verified Reddit account and posted 108 malicious advertisements over 48 hours, using social engineering ClickFix techniques to trick users into executing malicious commands
MITRE ATT&CK® Techniques
Valid Accounts
Phishing: Spearphishing Attachment
User Execution: Malicious File
Command and Scripting Interpreter: PowerShell
Command and Scripting Interpreter: Unix Shell
Deobfuscate/Decode Files or Information
Credentials from Password Stores: Credentials from Web Browsers
Steal Web Session Cookie
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Engineering Techniques
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
CISA ZTMM 2.0 – Privileged Account Management
Control ID: Identity.AM-6
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Entertainment/Movie Production
HBO Max account compromise demonstrates streaming platforms' vulnerability to information stealers targeting customer credentials and content distribution systems through social engineering attacks.
Internet
Reddit platform hijacking and malicious advertising showcase social media platforms' exposure to information stealing malware campaigns exploiting verified account trust mechanisms.
Computer Software/Engineering
ClickFix attacks targeting developers through fake AI tools and coding platforms highlight software industry's risk from information stealers compromising development environments.
Financial Services
Cryptocurrency wallet impersonation and clipboard hijacking malware directly threaten financial institutions' digital asset security and customer credential protection measures.
Sources
- Hackers hijack HBO Max Reddit account to push malware in ClickFix adshttps://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/Verified
- HBO Max Ads on a Compromised Reddit Account Exposed a Massive PasteSwitch ClickFix Operationhttps://www.hudsonrock.com/blog/hbo-max-ads-on-a-compromised-reddit-account-exposed-a-massive-pasteswitch-clickfix-operationVerified
- HBO Max Ads Exposed the PasteSwitch ClickFix Operationhttps://adamnet.works/blog/hbo-max-ads-exposed-the-pasteswitch-clickfix-operation/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this Reddit-based social engineering campaign by constraining lateral movement and limiting exfiltration paths from compromised endpoints within cloud workloads.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud workloads accessing the compromised Reddit content would likely have reduced exposure through identity-aware access controls and segmented application boundaries that limit user privilege scope within cloud environments.
Control: Zero Trust Segmentation
Mitigation: Workload isolation policies would likely limit the scope of privilege escalation by constraining compromised endpoints to their designated network segments and reducing access to sensitive cloud resources.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely prevent any attempted lateral movement between cloud workloads by enforcing strict inter-service communication policies and blocking unauthorized network traversal from compromised endpoints.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility controls would likely detect and constrain anomalous outbound communications to ember-bridge[.]com and other C2 infrastructure by identifying unauthorized network flows across multicloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely constrain data exfiltration by blocking unauthorized outbound transfers and limiting the volume of sensitive data that could be transmitted from compromised cloud workloads to external servers.
Despite Zero Trust controls reducing the attack surface, compromised endpoints could still execute clipboard manipulation attacks against local cryptocurrency applications, though the blast radius would be limited to isolated workload boundaries.
Impact at a Glance
Affected Business Functions
- Brand reputation management
- Social media marketing operations
- Customer engagement platforms
- Digital advertising campaigns
Estimated downtime: 2 days
Estimated loss: N/A
Potential exposure of Reddit account credentials for HBO Max official account. Users who interacted with malicious advertisements may have had browser credentials, cryptocurrency wallet data, Apple Notes, macOS passwords, Firefox profiles, and Telegram data compromised by MacSync and AMOS helper malware families.
Recommended Actions
Key Takeaways & Next Steps
- • Implement egress security and policy enforcement to block unauthorized outbound connections to attacker infrastructure like ember-bridge[.]com and prevent data exfiltration
- • Deploy inline IPS with Suricata signatures to detect and block known ClickFix attack patterns and malicious payload delivery attempts
- • Enable multicloud visibility and control to detect anomalous command execution patterns and suspicious automation behaviors across endpoints
- • Implement zero trust segmentation with least privilege policies to limit the impact of compromised user accounts and prevent credential abuse
- • Deploy cloud firewall with URL filtering and AI-powered traffic discovery to block access to malicious domains used in social engineering campaigns



