Kya hua
September 2026 me Hudson Rock aur ADAMnetworks ne dekha ki compromised u/hbomax se 48 ghante me 108 malicious ads paanch lure domains par chalaye gaye — isse PasteSwitch ClickFix operation expose hua.
Reddit par verified HBO Max account hack ho kar 48 ghante me 108 ClickFix ads chalane laga — hbomaxx.app, codex-craft.com aur teen aur nakli sites par.
ClickFix fake error dikhakar aapse Terminal ya Command Prompt me command paste karwata hai. Wahi command malware install kar deta hai, download nahi — isliye antivirus pakad nahi pata.
Mac par curl | zsh se MacSync aur AMOS browser logins aur Telegram data churate hain. Windows par mshta MP3/HTA polyglot chalakar AMSI disable karta hai aur Amatera ko memory me inject kar deta hai.
Crypto users ke liye risk aur bada hai: fake wallet apps 12/24-word phrases chura lete hain aur clipboard clippers Binance Smart Chain contracts se address badal dete hain — March se ab tak 36 rotations.
Kya confirm hai
Reddit ne confirm kiya HBO Max ad account compromise hua tha, lock kiya aur ads hataye. Researchers ne PasteSwitch ka macOS aur Windows infrastructure aur contract clippers confirm kiye.
- u/hbomax se 48 ghante me 108 ads — 40 hbomaxx.app se, 36 codex-craft.com se, baaki apple.clean-disk-guide.com, code-desktop.com, hbomax-macos.com se
- Amatera Schannel manual cert validation aur 77.91.65.13:443 par facebook.com SNI spoofing use karta hai
- Binance Smart Chain AnimateClipper/ZigClipper ne 36 baar rotate kiya — on-chain verifiable hai
Ab kya karein
Agar aapne command paste kiya hai to device ko compromised samjho. Websites ke diye commands ko Terminal ya Run me paste mat karo.
- Clean device se passwords badlo, 2FA on karo, wallet approvals revoke karo aur full malware scan karo
- Admins ke liye: mshta block karo, curl | zsh aur AMSI tampering monitor karo, 77.91.65.13 par SNI anomalies filter karo
Kyun matter karta hai
Jisne bhi woh nakli fix command Terminal ya Command Prompt me paste kiya, uske system me bina download ke MacSync, AMOS ya Amatera stealer install ho gaya jo passwords aur crypto chura leta hai.
Privacy
General Internet Users
Agar aap woh pasted command chala dete ho to browser passwords, Telegram data aur macOS keychain seconds me chori ho sakta hai — bina kuch download kiye.
Money
Cryptocurrency Holders
Fake wallet apps aur clipboard clippers transaction ke beech me aapka crypto address badal dete hain — paise Binance Smart Chain ke attacker contracts par chale jaate hain.
Work
Software Developers
User khud terminal command chalata hai isliye antivirus aur download filters bypass ho jaate hain — developers aur IT teams ko users ko training deni hogi ki unverified commands kabhi paste na karein.
Seedhi baat
Website ka diya hua fix kabhi Terminal me paste mat karo — wahi hack hai.
108 fake HBO ads ne users ko khud se hack karwaya — Terminal me paste karte hi passwords aur crypto gayab. Kabhi bhi web ka fix paste mat karo.
Verified sources (4)
ClickFix attacks are tricking Mac and Windows users into hacking themselves
↗HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation
↗HBO Max ads exposed the PasteSwitch ClickFix operation
↗Reddit administrator confirmation that malicious ads have been paused
↗Claims and linked sources
8 claimsClickFix attacks 2026 me rare trick se ek bade international operation me badal gaye hain jo Mac aur Windows dono ke users ko terminal me malicious command copy-paste karwa kar khud se hack karwate hain.
September 2026 me verified u/hbomax Reddit account hack hua aur 48 ghante me 108 malicious ClickFix ads chalaye gaye — paanch lure sites par: hbomaxx.app (40), codex-craft.com (36), apple.clean-disk-guide.com (15), code-desktop.com (11) aur hbomax-macos.com (6).
HBO Max ads ne PasteSwitch expose kiya — ek cross-platform ClickFix operation jo MacSync aur AMOS macOS stealers, InstallFix aur Amatera Windows loaders, nakli TLS SNI spoofing (77.91.65.13:443 par facebook.com dikhakar), fake wallet apps aur Binance Smart Chain clippers tak faila hua hai.
Windows par PasteSwitch mshta se InstallFix deliver karta hai jo MP3/HTA polyglot download karta hai, scheduled task banata hai, 32-bit PowerShell launch karta hai, AMSI disable karta hai, computer name aur username se victim-specific subdomain banata hai aur Amatera Stealer ko bina disk par likhe memory me inject kar deta hai.
PasteSwitch ke AnimateClipper aur ZigClipper Binance Smart Chain smart contracts ko mutable C2 dead drop ki tarah use karte hain getData() aur balanceOf se — March se July 2026 ke beech same controller ne 36 baar mainnet C2 badla.
Kyunki malware seedha Windows Command Prompt ya macOS Terminal se chalaya jaata hai — jo OS ka trusted interface hai — isliye kai ClickFix attacks antivirus aur browser download protection ko bypass kar jaate hain.
Reddit ne TechCrunch ko bataya ki HBO Max ka ads ke liye authorized account compromise hua tha aur malicious links ke liye use hua, company ne account lock kiya aur ads hata diye; ek admin ne publicly confirm kiya ki ads pause kar diye gaye.
macOS branch me curl | zsh se MacSync (browser credentials, Gecko profiles, Telegram data, Apple Notes, passwords /tmp/osalogging.zip se) aur AMOS Helper (.com.apple.accountsd me persist, /api/join/ aur /api/tasks se enroll) deliver hota hai.
Log kya keh rahe hain
Signal-only · not reporting“The ads have been paused and the account locked after compromise was detected.”