Saturday, 19 September India Edition
The Pulse
← Back to feed
TopOngoing1 hour ago

Hackers hijacked HBO Max Reddit ads to trick you into hacking yourself

A verified HBO Max Reddit account pushed 108 fake ads in 48 hours using copy-paste CAPTCHA tricks to install stealers on Mac and Windows.

01 / What happened

What happened

Attackers hijacked verified u/hbomax account and ran 108 ClickFix ads routing victims to fake sites like hbomaxx[.]us.

Hackers hijacked the verified HBO Max Reddit account and used it to push 108 malicious ads in just 48 hours, tricking both Mac and Windows users into infecting their own computers with a technique called ClickFix.

The campaign dubbed PasteSwitch posed as HBO Max OpenAI Codex and disk cleaners sending victims to domains like hbomaxx[.]us where a fake CAPTCHA told them to paste a command into Run or Terminal.

Because the command runs inside the trusted terminal it bypasses many antivirus tools and silently downloads info-stealers and crypto clippers.

Reddit paused the ads after a user flagged them in r/cybersecurity and opened an investigation while the compromise vector remains unclear.

Malicious adsDistinct ads served from hijacked u/hbomax account in 48 hours.
108
Blitz durationWindow before Reddit paused the ads.
48 hours
Timeline

Timeline

Key moments in the PasteSwitch blitz.

  • Sep 6 2026 - User flags HBO Max ads in r/cybersecurity.
  • Sep 12-14 2026 - 108 ClickFix lures served from verified account.
  • Sep 14 2026 - Researchers publish PasteSwitch analysis.
02 / Why it matters

Why it matters for me

Victims who pasted the fake verification command into Run PowerShell or Terminal silently installed malware stealing passwords and crypto.

Money

Financial-loss Β· Direct Β· High

General Public

Info-stealers and crypto clippers can drain bank sessions and swap wallet addresses causing direct money loss.

Privacy

Privacy Β· Direct Β· High

Mac Users

Pasting the fake CAPTCHA command gives malware terminal access to steal cookies and logins on Mac and Windows.

Safety

Security-risk Β· Indirect Β· High

General Public

Because ClickFix runs in your own terminal many antivirus tools miss it so awareness is key.

03 / The one thing

What to remember

The one thing
Never paste a command from a website into your terminal.

108 fake HBO Max ads. One copy-paste and your PC hacks itself. How ClickFix works.

Screenshot this, or share it

Verified sources (4)

Evidence behind the crack
Reporting/TechCrunch

ClickFix attacks are tricking Mac and Windows users into hacking themselves

β†—
PrimaryPublished Sep 14, 2026Accessed Sep 15, 2026
Research/InfoStealers (Hudson Rock)

HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation

β†—
CorroboratingPublished Sep 14, 2026Accessed Sep 15, 2026
Reporting/BleepingComputer

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

β†—
CorroboratingPublished Sep 14, 2026Accessed Sep 15, 2026
Reporting/The Register

HBO Max Reddit account compromised to serve ClickFix attacks

β†—
CorroboratingPublished Sep 14, 2026Accessed Sep 15, 2026

Claims and linked sources

6 claims
FactVerifiedHigh confidence

ClickFix shows a fake CAPTCHA instructing victims to paste a command into Run PowerShell or Terminal which installs malware evading AV.

ContextVerifiedHigh confidence

How attackers accessed the HBO Max Reddit account remains unclear and Warner Bros Discovery and Reddit did not respond to comments.

Community signals

Signal-only Β· not reporting
r/cybersecurity userreddit

β€œThe advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button / download. Clicking these opens up the classic infostealer/clickfix paste this command to download.”

Next story3 min read

Is the AI safety debate about safety or control?

Read next story