What happened
Attackers hijacked verified u/hbomax account and ran 108 ClickFix ads routing victims to fake sites like hbomaxx[.]us.
Hackers hijacked the verified HBO Max Reddit account and used it to push 108 malicious ads in just 48 hours, tricking both Mac and Windows users into infecting their own computers with a technique called ClickFix.
The campaign dubbed PasteSwitch posed as HBO Max OpenAI Codex and disk cleaners sending victims to domains like hbomaxx[.]us where a fake CAPTCHA told them to paste a command into Run or Terminal.
Because the command runs inside the trusted terminal it bypasses many antivirus tools and silently downloads info-stealers and crypto clippers.
Reddit paused the ads after a user flagged them in r/cybersecurity and opened an investigation while the compromise vector remains unclear.
Timeline
Key moments in the PasteSwitch blitz.
- Sep 6 2026 - User flags HBO Max ads in r/cybersecurity.
- Sep 12-14 2026 - 108 ClickFix lures served from verified account.
- Sep 14 2026 - Researchers publish PasteSwitch analysis.
Why it matters for me
Victims who pasted the fake verification command into Run PowerShell or Terminal silently installed malware stealing passwords and crypto.
Money
General Public
Info-stealers and crypto clippers can drain bank sessions and swap wallet addresses causing direct money loss.
Privacy
Mac Users
Pasting the fake CAPTCHA command gives malware terminal access to steal cookies and logins on Mac and Windows.
Safety
General Public
Because ClickFix runs in your own terminal many antivirus tools miss it so awareness is key.
What to remember
Never paste a command from a website into your terminal.
108 fake HBO Max ads. One copy-paste and your PC hacks itself. How ClickFix works.
Verified sources (4)
ClickFix attacks are tricking Mac and Windows users into hacking themselves
βHBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation
βHackers hijack HBO Max Reddit account to push malware in ClickFix ads
βHBO Max Reddit account compromised to serve ClickFix attacks
βClaims and linked sources
6 claimsIn September 2026 hackers compromised the verified u/hbomax Reddit account to push fake HBO Max ads delivering ClickFix malware.
Over 48 hours the hijacked account pushed 108 distinct malicious ads using multiple lures including HBO Max and OpenAI Codex.
The PasteSwitch campaign delivers info-stealers loaders crypto clippers and fake wallets across macOS and Windows.
ClickFix shows a fake CAPTCHA instructing victims to paste a command into Run PowerShell or Terminal which installs malware evading AV.
One lure domain was hbomaxx[.]us with other domains including codex-craft[.]com and apple.clean-disk-guide[.]com.
How attackers accessed the HBO Max Reddit account remains unclear and Warner Bros Discovery and Reddit did not respond to comments.
Community signals
Signal-only Β· not reportingβThe advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button / download. Clicking these opens up the classic infostealer/clickfix paste this command to download.β