Saturday, 19 September India Edition
The Pulse
← Back to feed
TopOngoing4 days ago

ClickFix Trick Makes You Hack Yourself: 108 Fake HBO Reddit Ads Exposed Massive PasteSwitch Operation

A hacked verified HBO Max Reddit account pushed 108 ClickFix ads in 48 hours, revealing a cross-platform campaign that steals passwords and crypto by making you paste a command into Terminal.

01 / What happened

What happened

Hudson Rock and ADAMnetworks researchers found 108 malicious ads from compromised u/hbomax over 48 hours in September 2026, exposing the PasteSwitch ClickFix operation across five lure domains.

A verified HBO Max account on Reddit was compromised and used to run 108 ClickFix ads in just 48 hours, spanning hbomaxx.app, codex-craft.com and three other lure sites.

ClickFix shows a fake error asking you to copy a command into Terminal or Command Prompt. That command — not a download — installs the malware, so antivirus often misses it.

On Mac the payload is MacSync and AMOS via curl | zsh stealing browser logins and Telegram data. On Windows mshta runs an MP3/HTA polyglot, disables AMSI, and injects Amatera Stealer straight into memory.

Crypto holders face extra risk: fake wallet apps steal 12/24-word phrases and clipboard clippers swap addresses using Binance Smart Chain contracts rotated 36 times since March 2026.

Fake ads from verified HBO Max accountOver 48 hours in September 2026 across 5 lure destinations
108
Deceptive C2 IP spoofing facebook.comAmatera presents facebook.com over TLS SNI to attacker IP to evade filtering
77.91.65.13:443
BSC contract C2 rotations Mar-Jul 2026AnimateClipper/ZigClipper smart contracts rotated C2 domain 36 times
36
What Is Confirmed

What is confirmed

Reddit confirmed the HBO Max ad account was compromised, locked it and removed ads. Researchers confirmed PasteSwitch infrastructure across macOS and Windows with contract-controlled clippers.

  • 108 ads in 48 hours from u/hbomax — 40 via hbomaxx.app, 36 via codex-craft.com, others via apple.clean-disk-guide.com, code-desktop.com, hbomax-macos.com
  • Amatera uses Schannel manual cert validation and SNI spoofing to 77.91.65.13:443 as facebook.com
  • Binance Smart Chain AnimateClipper/ZigClipper rotated 36 times — verifiable on-chain
Action Steps

What to do now

If you pasted a command, treat the device as compromised. Do not paste commands from websites into Terminal or Run dialogs.

  • Change passwords from a clean device, enable 2FA, revoke wallet approvals, and run a full malware scan
  • For admins: block mshta execution, monitor curl | zsh and AMSI tampering, filter SNI anomalies to 77.91.65.13
02 / Why it matters

Why it matters for me

Anyone who pasted the fake fix command into Terminal or Command Prompt silently installed MacSync, AMOS or Amatera stealers that steal passwords, Telegram data and crypto wallets without a download.

Privacy

Privacy · Direct · High

General Internet Users

Browser passwords, Telegram data and macOS keychain can be stolen in seconds if you run the pasted command — even without downloading a file.

Money

Financial-loss · Direct · High

Cryptocurrency Holders

Fake wallet apps and clipboard clippers swap your crypto address mid-transaction — funds can be redirected to attacker contracts on Binance Smart Chain.

Work

Security-risk · Indirect · High

Software Developers

User-executed terminal commands bypass antivirus and download filters, so developers and IT teams need to train users never to paste unverified commands.

03 / The one thing

What to remember

The one thing
Never copy-paste a fix from a website into Terminal — that is the hack.

108 fake HBO ads tricked users into hacking themselves — a paste into Terminal stole passwords and crypto. Never paste fixes from the web.

Screenshot this, or share it

Verified sources (4)

Evidence behind the crack
Reporting/TechCrunch

ClickFix attacks are tricking Mac and Windows users into hacking themselves

PrimaryPublished Sep 14, 2026Accessed Sep 15, 2026
Research/InfoStealers (Hudson Rock)

HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation

CorroboratingPublished Sep 14, 2026Accessed Sep 15, 2026
Research/ADAMnetworks

HBO Max ads exposed the PasteSwitch ClickFix operation

CorroboratingPublished Sep 13, 2026Accessed Sep 15, 2026
Official/Reddit (admin confirmation, via Hudson Rock)

Reddit administrator confirmation that malicious ads have been paused

CorroboratingPublished Sep 13, 2026Accessed Sep 15, 2026

Claims and linked sources

8 claims
FactVerifiedHigh confidence

ClickFix attacks have evolved from rare 2026 curiosities into a massive international operation that tricks victims on both Mac and Windows into copying and pasting malicious terminal commands to hack themselves.

NumberVerifiedHigh confidence

In September 2026 the verified official u/hbomax Reddit account was compromised and used to push 108 malicious ClickFix ads over 48 hours across five lure destinations: hbomaxx.app (40), codex-craft.com (36), apple.clean-disk-guide.com (15), code-desktop.com (11) and hbomax-macos.com (6).

FactVerifiedHigh confidence

The HBO Max ads exposed PasteSwitch, a cross-platform ClickFix operation spanning MacSync and AMOS macOS stealers, InstallFix and Amatera Windows loaders, deceptive TLS SNI spoofing (Amatera connects to 77.91.65.13:443 presenting facebook.com), fake wallet apps, and Binance Smart Chain contract-controlled crypto clippers.

FactVerifiedHigh confidence

On Windows PasteSwitch delivers InstallFix via mshta that downloads an MP3/HTA polyglot, creates a scheduled task, launches 32-bit PowerShell, disables AMSI, computes a victim-specific subdomain from computer name and username, and injects Amatera Stealer PE directly into memory without touching disk.

NumberVerifiedHigh confidence

PasteSwitch crypto clippers AnimateClipper and ZigClipper use Binance Smart Chain smart contracts as mutable C2 dead drops via getData() and balanceOf(address), with 36 mainnet C2 rotations by the same controller between March and July 2026.

ContextVerifiedHigh confidence

Because the malware is executed directly from Windows Command Prompt or macOS Terminal — a trusted OS interface — many ClickFix attacks evade antivirus and browser download protections that would block downloaded binaries.

FactVerifiedHigh confidence

Reddit told TechCrunch it learned an HBO Max account authorized to run ads was compromised and used for malicious links, and that it locked the account and removed the ads; an admin publicly confirmed the ads were paused.

FactVerifiedHigh confidence

The macOS branch delivers MacSync (exfiltrates browser credentials, Gecko profiles, Telegram data, Apple Notes, passwords via /tmp/osalogging.zip) and AMOS Helper (persists under .com.apple.accountsd, enrolls via /api/join/ and /api/tasks/) through curl | zsh commands.

Community signals

Signal-only · not reporting
Reddit administrator (via Hudson Rock screenshot)reddit

“The ads have been paused and the account locked after compromise was detected.”

Next story3 min read

Is the AI safety debate about safety or control?

Read next story