Cyber Resilience
← All news
Corroborated

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Our takeCorroborated: attackers hijacked the verified u/hbomax Reddit account and ran ClickFix malvertising ads that drop infostealers on Windows and macOS. If you clicked a suspicious HBO Max ad in the last 48 hours, scan your devices now.
Sources (3)
What this means for you — Security leader:Verify Reddit account advertising permissions and review recent sponsored posts for unauthorized activity. Block known ClickFix domains and educate users not to run pasted commands from ads or support pages.
What this means for you — Lean IT orgs:If you see an ad for HBO Max or any streaming service, do not click it or follow any instructions to paste commands into Run or Terminal. Use unique strong passwords on all accounts and turn on MFA everywhere you can.
What this means for you — MSP:Audit client social-media ad accounts (especially high-trust Reddit profiles) for unauthorized access and monitor for ClickFix-style malvertising campaigns. Add ClickFix IOCs to endpoint detection and user awareness training.
What this means for you — Researcher:Track the overlap between compromised high-trust accounts and ClickFix delivery; correlate with the ongoing rise in social-engineering malware loaders across Windows and macOS.