A compromised HBO Max Reddit account served over 100 malicious ClickFix ads, tricking users into pasting harmful execution scripts into their command lines.
- The verified HBO Max Reddit account was hijacked to serve more than 100 malicious advertisements.
- A Reddit user uncovered the infostealer campaign on September 6, highlighting fake macOS app promotions.
- Victims were directed to a lookalike domain at hbomaxx[.]us prompting manual command-line execution.
- Reddit administrators paused the malicious ads on September 9 and initiated an internal security investigation.
The official HBO Max Reddit account was compromised by attackers who used it to serve more than 100 malicious advertisements. These ads tricked Windows and macOS users into downloading infostealer malware through ClickFix social engineering tactics and fake application downloads.
Why Verified Corporate Accounts are the New Phishing Vectors
Corporate social media accounts carry an implicit trust factor that threat actors are aggressively exploiting to bypass basic perimeter defenses. When attackers compromised the verified HBO Max Reddit account, they did not just deface a profile; they weaponized an established identity to push more than 100 malicious advertisements over multiple days. According to The Register, a vigilant user uncovered the infostealer campaign on September 6, tracing the ad author to the legitimate handle and exposing a structural flaw in how major platforms vet paid promotional content. This incident marks a dangerous escalation in social media supply-chain attacks, where attackers leverage trusted brand handles to launder malicious infrastructure past both automated moderation filters and human intuition.
The mechanics of the attack relied entirely on social engineering paired with technical deception. The ads promoted a nonexistent native macOS application for HBO Max, exploiting a known gap in the streaming service's desktop ecosystem. Because many users expect major entertainment brands to offer standalone desktop clients, the proposition did not immediately trigger alarm bells. Once clicked, the ad routed visitors to a lookalike domain at hbomaxx[.]us, designed with enough fidelity to mimic official brand assets. Security analysts reviewing the campaign noted that this strategy deliberately lowers user guard rails by anchoring the interaction to a globally recognized trademark before introducing any technical manipulation.
To help security teams and IT administrators evaluate their exposure to this brand-impersonation vector, we can categorize social account compromise risks using a clear operational matrix.
The 3-Tier Corporate Account Risk Matrix
A systematic way to evaluate enterprise social media exposure based on authentication hygiene and platform privilege levels.
- Tier 1: Unmanaged Legacy Profiles - Old or forgotten marketing handles with weak passwords and no SSO enforcement, prime targets for credential stuffing and immediate weaponization.
- Tier 2: Authenticated Brand Handles - High-profile accounts with blue checks and ad-spending permissions enabled, where a single compromised session token lets attackers run paid malicious campaigns.
- Tier 3: Enterprise SSO Integrated - Highly secured accounts tied to corporate identity providers with hardware-token enforcement, audit logging, and strict least-privilege access rules.
How ClickFix Social Ads Trick Technical Users
What makes the ClickFix attack vector particularly lethal is its reliance on user-executed terminal commands rather than traditional binary exploits. Instead of dropping an opaque executable that modern endpoint detection and response tools might intercept, the landing page instructed victims to copy a PowerShell or Terminal command and paste it directly into their system interface. The Reddit security researcher who first flagged the HBO Max incident noted that this technique bypasses many conventional browser warnings because the user is technically performing the action themselves. On macOS systems, the script prompted the user to open Terminal, pasting a command designed to pull and execute credential-harvesting payloads without triggering standard Gatekeeper blocks.
This methodology shifts the burden of security entirely onto human judgment at the exact moment the user is distracted by a fake utility download. Endpoint security tools often struggle to flag these incidents because the process tree originates from a legitimate shell application invoked by the user. Threat actors understand that traditional malware delivery via direct downloads faces steep friction from modern operating systems, making social-engineered command-line execution the preferred bypass mechanism for sophisticated infostealer campaigns.
"My guess is that the Reddit account is compromised, leading to a classic infostealer and ClickFix paste-this-command routine." — Security Analyst & Reddit User
The campaign ran unchecked for days before platform moderators intervened. Reddit eventually paused the infostealer-dropping ads on September 9, with platform administrators confirming that safety and security teams had launched an internal investigation into the breach. Meanwhile, representatives for Warner Bros. Discovery, the parent company of HBO Max, did not immediately respond to inquiries regarding how the account credentials were compromised or whether multi-factor authentication was bypassed.
What to Watch Next
As platform-level ad fraud intersects with enterprise account takeovers, security leaders must monitor several key operational signals to protect their brand assets and user bases.
- Platform Ad Verification Audits: Track whether major social platforms introduce stricter multi-factor authentication requirements for ad-account creation and management tied to verified business profiles.
- Endpoint Command-Line Telemetry: Assess your organization's monitoring capabilities for anomalous copy-paste execution patterns in PowerShell and Terminal environments, especially following browser interactions.
- Brand Impersonation Domain Takedowns: Monitor how quickly domain registrars and hosting providers respond to lookalike domains leveraging major media trademarks for ClickFix distribution.
Frequently asked
What happened to the official HBO Max Reddit account?
The verified HBO Max Reddit account was compromised by threat actors who used it to serve more than 100 malicious advertisements promoting infostealer malware and ClickFix attacks.
What is a ClickFix attack?
A ClickFix attack is a social engineering technique where victims are tricked into copying and pasting malicious command-line instructions into their Windows PowerShell or macOS Terminal, executing malware directly.
How were macOS users targeted by the HBO Max Reddit breach?
Attackers used the compromised Reddit account to advertise a fake native macOS app for HBO Max, directing users to a lookalike domain that instructed them to run malicious Terminal commands.
How did Reddit respond to the compromised HBO Max ads?
Reddit paused the infostealer-dropping advertisements three days after they were first uncovered by a user, and platform administrators stated that safety and security teams began investigating the incident.
- hbo max reddit account compromised
- clickfix attacks windows macos
- hbo max reddit hacked infostealer
- malicious ads on reddit hbo max
- how do clickfix attacks work
- hbobig account takeover reddit
- what is clickfix malware
- hbo max macos app fake ad
- why are verified accounts getting hacked on reddit
- reddit security incident hbo max
