Spreely +
  • Home
  • Social
  • News
  • TV
  • Radio
  • Podcasts
  • Marketplace
  • Advertise
  • Home
  • Social
  • News
  • TV
  • Radio
  • Podcasts
  • Marketplace
  • Advertise

Spreely News

  • Politics
  • Business
  • Finance
  • Technology
  • Health
  • Sports
  • Politics
  • Business
  • Finance
  • Technology
  • Health
  • Sports
Home»Spreely News

Hackers Hijack HBO Max Verified Reddit Account, Spread Malware

Kevin ParkerBy Kevin ParkerSeptember 23, 2026 Spreely News No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Hackers found a nasty way to turn a trusted brand into a trap, using a verified HBO Max Reddit account to blast out malicious ads and funnel people toward malware. The campaign leaned on polished branding, fake downloads, and a trick that pushed victims to run dangerous commands themselves, which made the whole thing feel annoyingly ordinary until it was too late.

Researchers at Hudson Rock say the compromised account posted 108 malicious ads in about 48 hours. The pitches bounced between HBO Max downloads, AI tools, developer software, and Mac utilities, all while wearing the credibility of a verified corporate account that most users would have no reason to doubt.

The first bait was especially slick. A Reddit user reportedly spotted an ad from the verified u/hbomax account promoting what looked like a native HBO Max app for Mac, even though no such app exists. Instead of a normal download, the landing page pushed visitors toward copying a command into Terminal, which should instantly set off alarm bells.

That tactic is part of a growing scam style known as ClickFix. Instead of quietly installing malware in the background, the page nudges the victim into doing the risky step manually, often by pretending something is broken, like a CAPTCHA or browser setup issue. It is a clever hustle because it feels like routine troubleshooting, not a cyberattack.

In this case, the scam was tied to a wider operation researchers call PasteSwitch. The same campaign could shift depending on the device in front of it, sending Mac users down one path and Windows users down another, while keeping the same basic trick at the center of it all: paste this command and trust the page.

On Macs, the payloads were especially messy. Researchers said some branches could steal browser credentials, Telegram data, Apple Notes, and macOS passwords, while other parts kept access alive on infected systems. The campaign also played with fake cryptocurrency wallet apps like Ledger, Trezor Suite, and Exodus, aiming to steal recovery phrases that can empty a wallet fast.

Windows users were not getting a safer ride. Researchers found a branch using mshta and PowerShell, with one route disguising a malicious file as MP3/HTA content before creating a scheduled task and launching further code. Later stages could load the Amatera Stealer directly into memory, which is a tidy way for criminals to avoid leaving an obvious file behind.

See also  Squatter Hunter Shares Tech Tips To Stop Home Takeovers

Another ugly twist involved clipboard hijacking. Hudson Rock linked the operation to malware that could swap out copied cryptocurrency addresses, meaning a victim could paste what looked like the right wallet destination and still send money to the wrong place. That is the sort of scam that punishes even careful users who think they are checking every step.

The timing and scale mattered too. Researchers said the attackers kept switching domains and software lures as they went, showing how fast they can pivot once one page gets flagged or taken down. That kind of churn helps the same crew keep the scam alive while the branding changes around it.

Reddit later confirmed that an HBO Max account authorized to run ads on the platform was compromised and used to distribute malicious links. The company said it locked the account, removed the ads, and started working with HBO Max to strengthen security, while also saying no other advertising accounts appeared to be affected.

The bigger lesson is uncomfortable but simple. A verification badge and a polished ad can still lead straight into a trap if the account is compromised. The safest move is to ignore the ad, open a fresh tab, and go to the company’s site or official app store on your own instead of letting a slick promotion steer the traffic.

There is also a hard rule worth remembering: no legitimate website needs you to paste an unfamiliar command into Terminal, PowerShell, or the Windows Run box just to install ordinary software. If a page starts talking like a help desk technician but behaves like a pressure campaign, it is time to back out fast.

Attackers love simple patterns that work at scale, and this one has caught on because it shifts the final click onto the victim. That makes the scam harder to spot in the moment, especially when the page looks professional and the source appears to be a brand you already know.

Apple has started adding warnings on newer macOS versions when pasted text looks suspicious, but that is only one layer of defense. Security tools help, updates matter, and multifactor authentication is still worth turning on, yet the real edge comes from slowing down before any command gets pasted at all.

Technology
Avatar photo
Kevin Parker

Keep Reading

4 Top Load Washer Drawbacks That Buyers Should Know

4 DeWalt Tools Truck Drivers Should Have Ready

Can USC, Florida Sneak Into CFP? Klatt Names Top 10 Teams Outside Top 10 To Make CFP

Inside The 'Psychological Warfare' When NFL Backups Suddenly Become QB1

McDonald’s Unveils $8.5 Billion NEXT Plan For Restaurant Upgrades

GOP Lawmakers Probe Pro China Groups Fueling AI Data Center Protests

Add A Comment
Leave A Reply Cancel Reply

All Rights Reserved

Policies

  • Politics
  • Business
  • Finance
  • Technology
  • Health
  • Sports
  • Politics
  • Business
  • Finance
  • Technology
  • Health
  • Sports

Subscribe to our newsletter

Facebook X (Twitter) Instagram Pinterest
© 2026 Spreely Media. Turbocharged by AdRevv By Spreely.

Type above and press Enter to search. Press Esc to cancel.