Saturday, 19 September India Edition
The Pulse
← Back to feed
TopOngoing2 minutes ago

HBO Max Reddit account hack se ClickFix attack Mac Windows users khud system hack kar rahe hain

Verified HBO Max account se 48 ghante me 108 fake ads chalaye gaye fake CAPTCHA se command paste karwakar malware install karwaya.

01 / Kya hua

Kya hua

Hackers ne verified u/hbomax account hijack karke 108 ClickFix ads chalaye aur hbomaxx[.]us jaise fake sites par bheja.

Verified HBO Max ka Reddit account hack ho gaya aur 48 ghante me 108 fake ads se ClickFix malware baanta gaya Mac aur Windows users ko nishana banaya.

PasteSwitch naam ke attack me fake HBO Max aur Codex sites par CAPTCHA dikhakar Run ya Terminal me command paste karwaya jata hai.

Kyunki command apne terminal me chalta hai antivirus ise pakad nahi pata aur info-stealer chori kar leta hai.

Reddit ne ads pause karke investigation shuru ki lekin hack kaise hua abhi clear nahi hai.

Fake ads48 ghante me hijacked account se 108 ads chalaye gaye.
108
Attack durationReddit ke pause karne tak ka time window.
48 hours
Timeline

Timeline

PasteSwitch blitz ke main moments.

  • 6 Sep 2026 - User ne r/cybersecurity me ads flag kiye.
  • 12-14 Sep 2026 - Verified account se 108 lures chalaye gaye.
  • 14 Sep 2026 - Researchers ne PasteSwitch analysis publish ki.
02 / Kyun matter karta hai

Kyun matter karta hai

Jinhone Run ya Terminal me command paste kiya unke system par info-stealer aur crypto clipper chupke se install ho gaya.

Money

Financial-loss Β· Direct Β· High

General Public

Info-stealer aur crypto clipper bank session aur wallet address chura kar seedha paiso ka nuksaan kara sakta hai.

Privacy

Privacy Β· Direct Β· High

Mac Users

Fake CAPTCHA ka command paste karte hi malware ko terminal access mil jata hai aur wo cookies aur logins chura leta hai.

Safety

Security-risk Β· Indirect Β· High

General Public

Kyunki ClickFix aapke terminal me chalta hai antivirus ise miss kar deta hai isliye jankari hi bachav hai.

03 / Seedhi baat

Seedhi baat

Seedhi baat
Website ke kehne par terminal me command kabhi paste mat karo.

108 fake ads ek copy-paste aur system hack ClickFix kaise kaam karta hai.

Screenshot ya share kar lo

Verified sources (4)

Evidence behind the crack
Reporting/TechCrunch

ClickFix attacks are tricking Mac and Windows users into hacking themselves

β†—
PrimaryPublished Sep 14, 2026Accessed Sep 15, 2026
Research/InfoStealers (Hudson Rock)

HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation

β†—
CorroboratingPublished Sep 14, 2026Accessed Sep 15, 2026
Reporting/BleepingComputer

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

β†—
CorroboratingPublished Sep 14, 2026Accessed Sep 15, 2026
Reporting/The Register

HBO Max Reddit account compromised to serve ClickFix attacks

β†—
CorroboratingPublished Sep 14, 2026Accessed Sep 15, 2026

Claims and linked sources

6 claims
FactVerifiedHigh confidence

ClickFix shows a fake CAPTCHA instructing victims to paste a command into Run PowerShell or Terminal which installs malware evading AV.

ContextVerifiedHigh confidence

How attackers accessed the HBO Max Reddit account remains unclear and Warner Bros Discovery and Reddit did not respond to comments.

Log kya keh rahe hain

Signal-only Β· not reporting
r/cybersecurity userreddit

β€œThe advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button / download. Clicking these opens up the classic infostealer/clickfix paste this command to download.”

Agli story3 min read

Meta ka Muse Mac pe aaya β€” ab AI aapke computer pe kaam kar sakti hai

Agli story padhein