Saturday, 19 September India Edition
The Pulse
← Back to feed
TopOngoing4 days ago

ClickFix Ka Naya Jaal: 108 Fake HBO Reddit Ads Ne PasteSwitch Scam Ko Expose Kiya

Hack hua verified HBO Max Reddit account ne 48 ghante me 108 ClickFix ads chalaye — ye cross-platform campaign aapse Terminal me command paste karwa kar passwords aur crypto chura leta hai.

01 / Kya hua

Kya hua

September 2026 me Hudson Rock aur ADAMnetworks ne dekha ki compromised u/hbomax se 48 ghante me 108 malicious ads paanch lure domains par chalaye gaye — isse PasteSwitch ClickFix operation expose hua.

Reddit par verified HBO Max account hack ho kar 48 ghante me 108 ClickFix ads chalane laga — hbomaxx.app, codex-craft.com aur teen aur nakli sites par.

ClickFix fake error dikhakar aapse Terminal ya Command Prompt me command paste karwata hai. Wahi command malware install kar deta hai, download nahi — isliye antivirus pakad nahi pata.

Mac par curl | zsh se MacSync aur AMOS browser logins aur Telegram data churate hain. Windows par mshta MP3/HTA polyglot chalakar AMSI disable karta hai aur Amatera ko memory me inject kar deta hai.

Crypto users ke liye risk aur bada hai: fake wallet apps 12/24-word phrases chura lete hain aur clipboard clippers Binance Smart Chain contracts se address badal dete hain — March se ab tak 36 rotations.

Verified HBO Max account se fake adsSeptember 2026 me 48 ghante me 5 nakli sites par
108
Facebook.com ke naam par nakli C2 IPAmatera attacker IP par facebook.com dikhakar TLS SNI filtering ko bypass karta hai
77.91.65.13:443
BSC contract C2 rotations Mar-Jul 2026AnimateClipper/ZigClipper contracts ne 36 baar C2 domain badla
36
What Is Confirmed

Kya confirm hai

Reddit ne confirm kiya HBO Max ad account compromise hua tha, lock kiya aur ads hataye. Researchers ne PasteSwitch ka macOS aur Windows infrastructure aur contract clippers confirm kiye.

  • u/hbomax se 48 ghante me 108 ads — 40 hbomaxx.app se, 36 codex-craft.com se, baaki apple.clean-disk-guide.com, code-desktop.com, hbomax-macos.com se
  • Amatera Schannel manual cert validation aur 77.91.65.13:443 par facebook.com SNI spoofing use karta hai
  • Binance Smart Chain AnimateClipper/ZigClipper ne 36 baar rotate kiya — on-chain verifiable hai
Action Steps

Ab kya karein

Agar aapne command paste kiya hai to device ko compromised samjho. Websites ke diye commands ko Terminal ya Run me paste mat karo.

  • Clean device se passwords badlo, 2FA on karo, wallet approvals revoke karo aur full malware scan karo
  • Admins ke liye: mshta block karo, curl | zsh aur AMSI tampering monitor karo, 77.91.65.13 par SNI anomalies filter karo
02 / Kyun matter karta hai

Kyun matter karta hai

Jisne bhi woh nakli fix command Terminal ya Command Prompt me paste kiya, uske system me bina download ke MacSync, AMOS ya Amatera stealer install ho gaya jo passwords aur crypto chura leta hai.

Privacy

Privacy · Direct · High

General Internet Users

Agar aap woh pasted command chala dete ho to browser passwords, Telegram data aur macOS keychain seconds me chori ho sakta hai — bina kuch download kiye.

Money

Financial-loss · Direct · High

Cryptocurrency Holders

Fake wallet apps aur clipboard clippers transaction ke beech me aapka crypto address badal dete hain — paise Binance Smart Chain ke attacker contracts par chale jaate hain.

Work

Security-risk · Indirect · High

Software Developers

User khud terminal command chalata hai isliye antivirus aur download filters bypass ho jaate hain — developers aur IT teams ko users ko training deni hogi ki unverified commands kabhi paste na karein.

03 / Seedhi baat

Seedhi baat

Seedhi baat
Website ka diya hua fix kabhi Terminal me paste mat karo — wahi hack hai.

108 fake HBO ads ne users ko khud se hack karwaya — Terminal me paste karte hi passwords aur crypto gayab. Kabhi bhi web ka fix paste mat karo.

Screenshot ya share kar lo

Verified sources (4)

Evidence behind the crack
Reporting/TechCrunch

ClickFix attacks are tricking Mac and Windows users into hacking themselves

PrimaryPublished Sep 14, 2026Accessed Sep 15, 2026
Research/InfoStealers (Hudson Rock)

HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation

CorroboratingPublished Sep 14, 2026Accessed Sep 15, 2026
Research/ADAMnetworks

HBO Max ads exposed the PasteSwitch ClickFix operation

CorroboratingPublished Sep 13, 2026Accessed Sep 15, 2026
Official/Reddit (admin confirmation, via Hudson Rock)

Reddit administrator confirmation that malicious ads have been paused

CorroboratingPublished Sep 13, 2026Accessed Sep 15, 2026

Claims and linked sources

8 claims
FactVerifiedHigh confidence

ClickFix attacks 2026 me rare trick se ek bade international operation me badal gaye hain jo Mac aur Windows dono ke users ko terminal me malicious command copy-paste karwa kar khud se hack karwate hain.

NumberVerifiedHigh confidence

September 2026 me verified u/hbomax Reddit account hack hua aur 48 ghante me 108 malicious ClickFix ads chalaye gaye — paanch lure sites par: hbomaxx.app (40), codex-craft.com (36), apple.clean-disk-guide.com (15), code-desktop.com (11) aur hbomax-macos.com (6).

FactVerifiedHigh confidence

HBO Max ads ne PasteSwitch expose kiya — ek cross-platform ClickFix operation jo MacSync aur AMOS macOS stealers, InstallFix aur Amatera Windows loaders, nakli TLS SNI spoofing (77.91.65.13:443 par facebook.com dikhakar), fake wallet apps aur Binance Smart Chain clippers tak faila hua hai.

FactVerifiedHigh confidence

Windows par PasteSwitch mshta se InstallFix deliver karta hai jo MP3/HTA polyglot download karta hai, scheduled task banata hai, 32-bit PowerShell launch karta hai, AMSI disable karta hai, computer name aur username se victim-specific subdomain banata hai aur Amatera Stealer ko bina disk par likhe memory me inject kar deta hai.

NumberVerifiedHigh confidence

PasteSwitch ke AnimateClipper aur ZigClipper Binance Smart Chain smart contracts ko mutable C2 dead drop ki tarah use karte hain getData() aur balanceOf se — March se July 2026 ke beech same controller ne 36 baar mainnet C2 badla.

ContextVerifiedHigh confidence

Kyunki malware seedha Windows Command Prompt ya macOS Terminal se chalaya jaata hai — jo OS ka trusted interface hai — isliye kai ClickFix attacks antivirus aur browser download protection ko bypass kar jaate hain.

FactVerifiedHigh confidence

Reddit ne TechCrunch ko bataya ki HBO Max ka ads ke liye authorized account compromise hua tha aur malicious links ke liye use hua, company ne account lock kiya aur ads hata diye; ek admin ne publicly confirm kiya ki ads pause kar diye gaye.

FactVerifiedHigh confidence

macOS branch me curl | zsh se MacSync (browser credentials, Gecko profiles, Telegram data, Apple Notes, passwords /tmp/osalogging.zip se) aur AMOS Helper (.com.apple.accountsd me persist, /api/join/ aur /api/tasks se enroll) deliver hota hai.

Log kya keh rahe hain

Signal-only · not reporting
Reddit administrator (via Hudson Rock screenshot)reddit

“The ads have been paused and the account locked after compromise was detected.”

Agli story3 min read

Meta ka Muse Mac pe aaya — ab AI aapke computer pe kaam kar sakti hai

Agli story padhein