Hackers Hijack Official HBO Max Reddit Account for Malware Campaign
PUBLISHED Sep 15, 2026, 9:56 AM ET
Read, Watch or Listen
Cybersecurity researchers discovered that malicious actors compromised the official verified Reddit account of streaming service HBO Max to distribute deceptive advertisements. During a recent two day window, the attackers published one hundred eight fraudulent ads pushing fake applications and developer tools. Clicking these links directed users to malicious landing pages utilizing social engineering techniques known as ClickFix. Visitors were manipulated into executing obfuscated terminal commands that installed infostealer malware across Windows and macOS systems. Security firms Hudson Rock and ADAMnetworks linked this activity to a broader campaign named PasteSwitch. The malware extracted sensitive browser credentials, crypto wallet recovery phrases, and session tokens. Threat actors engaged smart contracts on the Binance network to host dynamic command infrastructure. Reddit security teams eventually secured the compromised account and paused the malicious advertisements. Warner Bros Discovery representatives faced inquiries regarding authentication vulnerabilities. The incident underscores growing corporate social media security platform risks faced today.
By Shahbaz A. | JQJO News
Timeline of Events
- September 13, 2026 — attackers successfully compromised the official verified HBO Max Reddit account.
- September 13, 2026 — malicious threat actors began publishing fraudulent advertisements across the platform.
- September 14, 2026 — researcher Alex Cutts publicly identified suspicious advertisements posted by hbomax.
- September 14, 2026 — security firms Hudson Rock started analyzing malicious ad campaign activities.
- September 14, 2026 — ADAMnetworks researchers linked the breach to broader PasteSwitch malware operations.
- September 15, 2026 — technical reports detailed ClickFix social engineering malware delivery mechanism techniques.
- September 15, 2026 — investigators revealed infostealer payloads targeting both Windows and macOS systems.
- September 15, 2026 — security teams paused malicious advertisements and secured the compromised account.
- September 15, 2026 — public awareness grew regarding corporate social media account security vulnerabilities.
- September 15, 2026 — investigations continue examining unauthorized access vectors affecting verified corporate profiles.
News Intelligence
- Immediate US impact: Users faced immediate risks from malicious software download ad campaigns.
- Possible long-term US impact: Companies must enhance security protocols for verified social media channels.
- Most affected groups: Social media advertisers, enterprise security teams, and everyday platform users.
- Reader priority: Readers should avoid clicking unverified ads and update security settings.
- Articles Published:
- 11
- Right Leaning:
- 1
- Left Leaning:
- 1
- Neutral:
- 9
- Distribution:
- Left 9%, Center 82%, Right 9%
Left: Emphasizes corporate accountability and platform security failures protecting digital consumers. Center: Focuses strictly on technical breach details and cybersecurity mitigation steps. Right: Highlights regulatory compliance and economic impacts on digital business operations.
Help Net Security reported compromised HBO Max Reddit account details. https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/
Coverage of Story:
From Center
HBO Max Reddit account hijacked for ClickFix infostealer campaign
Help Net Security Dark Reading Forbes PCMag Bloomberg Reuters AP News Financial Times NewsweekFrom Right
Hackers exploit verified Reddit advertising privileges for malware distribution
Wall Street Journal
Comments