Hackers found a nasty way to turn a trusted brand into a trap, using a verified HBO Max Reddit account to blast out malicious ads and funnel people toward malware. The campaign leaned on polished branding, fake downloads, and a trick that pushed victims to run dangerous commands themselves, which made the whole thing feel annoyingly ordinary until it was too late.
Researchers at Hudson Rock say the compromised account posted 108 malicious ads in about 48 hours. The pitches bounced between HBO Max downloads, AI tools, developer software, and Mac utilities, all while wearing the credibility of a verified corporate account that most users would have no reason to doubt.
The first bait was especially slick. A Reddit user reportedly spotted an ad from the verified u/hbomax account promoting what looked like a native HBO Max app for Mac, even though no such app exists. Instead of a normal download, the landing page pushed visitors toward copying a command into Terminal, which should instantly set off alarm bells.
That tactic is part of a growing scam style known as ClickFix. Instead of quietly installing malware in the background, the page nudges the victim into doing the risky step manually, often by pretending something is broken, like a CAPTCHA or browser setup issue. It is a clever hustle because it feels like routine troubleshooting, not a cyberattack.
In this case, the scam was tied to a wider operation researchers call PasteSwitch. The same campaign could shift depending on the device in front of it, sending Mac users down one path and Windows users down another, while keeping the same basic trick at the center of it all: paste this command and trust the page.
On Macs, the payloads were especially messy. Researchers said some branches could steal browser credentials, Telegram data, Apple Notes, and macOS passwords, while other parts kept access alive on infected systems. The campaign also played with fake cryptocurrency wallet apps like Ledger, Trezor Suite, and Exodus, aiming to steal recovery phrases that can empty a wallet fast.
Windows users were not getting a safer ride. Researchers found a branch using mshta and PowerShell, with one route disguising a malicious file as MP3/HTA content before creating a scheduled task and launching further code. Later stages could load the Amatera Stealer directly into memory, which is a tidy way for criminals to avoid leaving an obvious file behind.
Another ugly twist involved clipboard hijacking. Hudson Rock linked the operation to malware that could swap out copied cryptocurrency addresses, meaning a victim could paste what looked like the right wallet destination and still send money to the wrong place. That is the sort of scam that punishes even careful users who think they are checking every step.
The timing and scale mattered too. Researchers said the attackers kept switching domains and software lures as they went, showing how fast they can pivot once one page gets flagged or taken down. That kind of churn helps the same crew keep the scam alive while the branding changes around it.
Reddit later confirmed that an HBO Max account authorized to run ads on the platform was compromised and used to distribute malicious links. The company said it locked the account, removed the ads, and started working with HBO Max to strengthen security, while also saying no other advertising accounts appeared to be affected.
The bigger lesson is uncomfortable but simple. A verification badge and a polished ad can still lead straight into a trap if the account is compromised. The safest move is to ignore the ad, open a fresh tab, and go to the company’s site or official app store on your own instead of letting a slick promotion steer the traffic.
There is also a hard rule worth remembering: no legitimate website needs you to paste an unfamiliar command into Terminal, PowerShell, or the Windows Run box just to install ordinary software. If a page starts talking like a help desk technician but behaves like a pressure campaign, it is time to back out fast.
Attackers love simple patterns that work at scale, and this one has caught on because it shifts the final click onto the victim. That makes the scam harder to spot in the moment, especially when the page looks professional and the source appears to be a brand you already know.
Apple has started adding warnings on newer macOS versions when pasted text looks suspicious, but that is only one layer of defense. Security tools help, updates matter, and multifactor authentication is still worth turning on, yet the real edge comes from slowing down before any command gets pasted at all.
