Kya hua
Hackers ne verified u/hbomax account hijack karke 108 ClickFix ads chalaye aur hbomaxx[.]us jaise fake sites par bheja.
Verified HBO Max ka Reddit account hack ho gaya aur 48 ghante me 108 fake ads se ClickFix malware baanta gaya Mac aur Windows users ko nishana banaya.
PasteSwitch naam ke attack me fake HBO Max aur Codex sites par CAPTCHA dikhakar Run ya Terminal me command paste karwaya jata hai.
Kyunki command apne terminal me chalta hai antivirus ise pakad nahi pata aur info-stealer chori kar leta hai.
Reddit ne ads pause karke investigation shuru ki lekin hack kaise hua abhi clear nahi hai.
Timeline
PasteSwitch blitz ke main moments.
- 6 Sep 2026 - User ne r/cybersecurity me ads flag kiye.
- 12-14 Sep 2026 - Verified account se 108 lures chalaye gaye.
- 14 Sep 2026 - Researchers ne PasteSwitch analysis publish ki.
Kyun matter karta hai
Jinhone Run ya Terminal me command paste kiya unke system par info-stealer aur crypto clipper chupke se install ho gaya.
Money
General Public
Info-stealer aur crypto clipper bank session aur wallet address chura kar seedha paiso ka nuksaan kara sakta hai.
Privacy
Mac Users
Fake CAPTCHA ka command paste karte hi malware ko terminal access mil jata hai aur wo cookies aur logins chura leta hai.
Safety
General Public
Kyunki ClickFix aapke terminal me chalta hai antivirus ise miss kar deta hai isliye jankari hi bachav hai.
Seedhi baat
Website ke kehne par terminal me command kabhi paste mat karo.
108 fake ads ek copy-paste aur system hack ClickFix kaise kaam karta hai.
Verified sources (4)
ClickFix attacks are tricking Mac and Windows users into hacking themselves
↗HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation
↗Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
↗HBO Max Reddit account compromised to serve ClickFix attacks
↗Claims and linked sources
6 claimsIn September 2026 hackers compromised the verified u/hbomax Reddit account to push fake HBO Max ads delivering ClickFix malware.
Over 48 hours the hijacked account pushed 108 distinct malicious ads using multiple lures including HBO Max and OpenAI Codex.
The PasteSwitch campaign delivers info-stealers loaders crypto clippers and fake wallets across macOS and Windows.
ClickFix shows a fake CAPTCHA instructing victims to paste a command into Run PowerShell or Terminal which installs malware evading AV.
One lure domain was hbomaxx[.]us with other domains including codex-craft[.]com and apple.clean-disk-guide[.]com.
How attackers accessed the HBO Max Reddit account remains unclear and Warner Bros Discovery and Reddit did not respond to comments.
Log kya keh rahe hain
Signal-only · not reporting“The advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button / download. Clicking these opens up the classic infostealer/clickfix paste this command to download.”