Back to news
Cybersecurity Alert
September 15, 2026 by EmailMeNow IT Consulting

Hijacked HBO Max Reddit Account Pushed Fake Ads That Drop Malware

Attackers used verified u/hbomax ads for a 48-hour ClickFix blitz. Max streaming is not reported hacked. Audits (ideal 100%): ic3.gov 87%, reddit.com 85%, hbomax.com 67%, max.com 52%.

Source: Hudson Rock · ADAMnetworks · Malwarebytes

NewsPhishingMalwareClickFixRedditHBO MaxMFAYubiKeyAuthenticator AppsCybersecurity
Laptop on a coffee table showing a verified social-feed ad for a streaming app, with a sticky note that says type the app store yourself

Attackers took over HBO Max’s verified Reddit account (u/hbomax) and used its trusted ad status to run a 48-hour malvertising blitz. Hudson Rock and ADAMnetworks counted 108 distinct ads. Clicking them sent Windows and Mac users to lookalike download pages that asked them to paste a command — the ClickFix pattern — then dropped infostealers, loaders, fake wallets, and crypto clippers.

This is not a reported hack of HBO Max’s streaming platform. PCMag said Warner / HBO Max had not commented as of mid-September. Reddit paused the ads and opened a security review. It is also not a duplicate of ChatGPT share-link malware (real OpenAI share URLs, not a hijacked brand account) or ClickLock Stealer (a different ClickFix locker family).

A Reddit user flagged a macOS HBO Max app ad from u/hbomax on September 6, 2026. HBO Max does not ship a native Mac app. Treat any “download HBO Max for Mac” ad as hostile.

Laptop on a coffee table showing a verified social-feed ad for a streaming app, with a sticky note that says type the app store yourself

Snapshot

FieldDetail
What happenedVerified u/hbomax ads → ClickFix paste pages
WindowAbout 48 hours; first public report Sept 6
Scale108 ads · 46 used an HBO Max lure
Max streamingNot reported breached
CourtListenerNo matching campaign dockets as of Sept 15, 2026

What the ads did

Researchers named the wider delivery system PasteSwitch: the victim pastes one command, then the kit switches payload by OS and lure. Help Net Security and The Register match Hudson Rock’s ad mix:

LureAdsDefanged landing
Fake HBO Max app46hbomaxx[.]app · hbomax-macos[.]com
Fake OpenAI Codex36codex-craft[.]com
Fake Mac disk utility15apple.clean-disk-guide[.]com
Other “dev tools”11code-desktop[.]com

The first reporter also named hbomaxx[.]us. We do not link those hosts. Malwarebytes says some visitors saw a blank page or a redirect to a real vendor, which hid the kit from scanners.

macOS paths described by researchers used a paste-into-Terminal style drop and stealers such as MacSync and AMOS (browsers, Telegram, Notes, saved passwords, wallet seed phrases). Windows paths used a Run / PowerShell / mshta style drop toward an in-memory loader and Amatera. Clippers (AnimateClipper / ZigClipper) swap copied crypto addresses; Hudson Rock says some C2 hints sat in Binance Smart Chain contracts (36 mainnet changes March–July 2026). Those names are researcher labels, not a company attribution from Reddit or Warner.

We do not reprint commands, hashes, or live lure URLs.

Fake streaming download page beside redacted Terminal and Run dialogs with a note never to paste from an ad

Were you affected — what to do

You are in scope if you clicked a Reddit ad from u/hbomax around September 6–8 (the ~48-hour window after the first report) and followed on-screen paste / Run / Terminal steps — or installed a “Mac HBO Max app,” Codex desktop, or disk-cleaner from that ad.

  1. Do not paste anything a webpage copied for you. Close the tab. Do not “finish setup.”
  2. Stream only from the Max / HBO Max app or site you already have, or type max.com / hbomax.com yourself. There is no official native Mac HBO Max installer in an ad.
  3. If you already pasted or ran the prompt: take the device offline. From a clean computer, change Reddit, email, bank, and crypto-wallet passwords. Assume browser cookies and saved passwords may be gone. Rotate wallet keys if you use crypto.
  4. Scan with an up-to-date endpoint product. Malwarebytes says it blocks ember-bridge[.]com as PasteSwitch infrastructure — still do not visit it.
  5. Report at IC3 and ReportFraud.ftc.gov. On macOS Tahoe 26.4+, Apple’s Terminal paste warning helps some people — do not rely on it.

A hardware key on Reddit does not undo a command you already ran. It does cut a lot of the follow-on fake logins that show up after an infostealer.

MFA: YubiKey and Google Authenticator

ClickFix never needs your second factor. It needs you to run attacker code. Grades match our MFA directory.

GradeMeaning
FailSMS, voice, or email OTP — or no public MFA path
PassSelf-serve Google Authenticator-style open TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
PlatformGradeYubiKeyAuthenticator
RedditPassNoYes
HBO Max / MaxFailNoNo

Reddit’s 2FA help documents a 6-digit authenticator app (Google Authenticator-class). Passkeys are also documented. Public Reddit 2FA pages do not name a YubiKey enrollment path, so this row is Pass, not Strong. Brand-account 2FA still would not have stopped a session that was already stolen.

HBO Max account-security help covers unique passwords, device lists, and phishing. It does not document YubiKey or Google Authenticator. SMS appears only when adding an email to a phone-created account. That is Fail.

Directory: MFA support directory · Category → Social & Professional (Reddit) and Email & Identity (Max).

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key and phone authenticator beside a streaming login that only shows email and password

Independent cybersecurity audits

We audited official Reddit, Max, HBO Max, and reporting hosts on September 15, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not explain how u/hbomax was taken over.

OrganizationDomainOverallvs 100%
FBI IC3ic3.gov87%−13
Redditreddit.com85%−15
HBO Maxhbomax.com67%−33
Maxmax.com52%−48
DomainIdentityTransportWebsite
ic3.gov90%45%97%
reddit.com90%15%95%
hbomax.com50%15%87%
max.com50%15%37%

Audit links: ic3.gov · reddit.com · hbomax.com · max.com

reddit.com at 85% is still −15 from the ideal. Transport 15% on Reddit and both Max hosts is a mail-transport gap — not a reason to trust a “Max desktop” ad. Parent wbd.com scored 61% (not in the four-row board). Researcher host malwarebytes.com scored 71%. ic3.gov is the reporting host.

Domain audit scoreboard versus the 100 percent ideal

Website stack note

Passive website-tech probes on September 15, 2026:

DomainStack signal
reddit.comStack undetected; DigiCert TLS expires 2027-02-16
max.comStack undetected; Amazon TLS expires 2027-03-04
hbomax.comengage-v2 (X-Powered-By); Amazon TLS expires 2027-01-03
wbd.comDrupal (version hidden); Amazon TLS expires 2027-02-23
ic3.govStack undetected; DigiCert TLS expires 2027-01-05

Point-in-time only. A live marketing homepage is not a forensic finding on the Reddit ad account.

Blacklist and lookalike domains

Email blacklist checks (public DoH, September 15, 2026): reddit.com, max.com, hbomax.com, wbd.com, and ic3.gov were clear on mail/domain lists we can query. Reddit web/CDN IPs showed informational SPFBL notes. Do not lead as “Reddit is blacklisted.”

We did not HTTP-probe malware landing pages. DNS lookalike scans (BEC profile, registered signals only) on the official brands:

Brand scannedTo reviewLikely ownedBEC staging
reddit.com8461
hbomax.com5201
max.com7010
wbd.com6403

max.com is a three-letter name, so most “lookalikes” are unrelated generic brands (including mac.com). Do not treat that list as Max phishing. High-interest registered names on the HBO Max / Reddit scans (investigate; not proof this campaign used them):

LookalikeTechniqueNote
hbomaxx.comduplicationSame extra-x pattern as hbomaxx[.]app / [.]us
hbornax.comhomoglyphBEC staging (NS + MX)
hb0max.comhomoglyphRegistered (NS + MX)
r3ddit.comhomoglyphBEC staging (NS + MX)
w-bd.comhyphenationBEC staging — parent ticker host

Type max.com or hbomax.com yourself. Continuous monitoring: Cybersquat Domain Monitoring.


Run a free audit at audit.emailmenow.com or contact EmailMeNow for DMARC / MTA-STS and phishing-resistant MFA aimed at the 100% ideal.


Sources: Hudson Rock — PasteSwitch / u/hbomax ads · ADAMnetworks · Malwarebytes (Sept 15) · Help Net Security · The Register · PCMag · Reddit 2FA and passkeys on signup · HBO Max account security. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 15, 2026. Domain scores: audit.emailmenow.com only. No matching RECAP/docket hits for this campaign.