Skip to the story
All stories

HBO Max Reddit account hijacked to push malware

Malicious ads used a social engineering trick to infect Windows and macOS devices.

AI-assisted coverage comparison, editor-supervised · How this was made

Published
HBO Max Reddit account hijacked to push malware

What this story says

  • Hackers compromised the official HBO Max Reddit account, using it to post malicious advertisements.
  • The compromised account was used to launch 108 ads over about 48 hours, targeting Windows and macOS users.
  • The ads employed a social engineering technique known as ClickFix, prompting users to copy and paste commands into their operating systems.
  • Security researchers from Hudson Rock and ADAMnetworks analyzed the campaign, linking it to a larger operation called PasteSwitch.

Who covered it

Left 67%(2)Centre 33%(1)Right 0%(0)

Percentages are shares of the 3 outlets carrying a published leaning rating. 10 of the 13 outlets we know ran this story carry no rating and are not counted in them. Coverage measured .

Trust

42/100

Craft

61/100

Hype

41/100

13 sources · methodology

Hackers gained control of the official HBO Max Reddit account and used it to distribute malicious advertisements. These ads were designed to trick users into infecting their Windows and macOS devices with information-stealing malware through a technique called ClickFix. The compromised account posted approximately 108 such advertisements over a period of about 48 hours.

The ClickFix attack method involves social engineering, where users are prompted to copy and paste commands into their operating system's command line interface, such as Windows Run, PowerShell, or macOS Terminal. This action, performed by the user themselves, can bypass some security software. The advertisements, while sometimes impersonating HBO Max, also promoted fake AI tools, developer software, and macOS utilities, broadening the potential reach of the campaign.

Disagreement on response time

TechCrunch reported that Reddit stated it "recently learned that an HBO Max account authorized to run advertisements on Reddit was compromised and used to run ads containing malicious links," and that the company locked the account and removed the ads. Reddit did not specify how many users were targeted or clicked the ads. BleepingComputer noted that HBO and Warner Bros. Discovery had not responded to questions about the incident.

What the coverage left out

None of the reports printed below mention any specific number of users who clicked on the malicious ads or were ultimately compromised. TechCrunch noted it was unclear how many people were affected, and Reddit declined to provide figures when asked. Warner Brothers Discovery did not respond to requests for comment in the TechCrunch report.

Still developing. We have re-checked which outlets are covering this 9 times, most recently on 15 Sept 2026, 00:00, and will add the sides that appear.

How other outlets pictured it

Which photograph to run is each newsroom’s own choice. The leaning beside a name is that outlet’s published rating, not a claim that the pictures divide along it. Every picture is shown from the outlet’s own server and links to the article it ran in.

HBO Max Reddit account hijacked to push malware
BleepingComputerCentre

How each side covered it

Our own reading of the reporting listed below, written from the outlets’ articles rather than quoted from them. The reasoning is set out on our methodology page.

Left

2 rated outlets

  • The left-rated reports led on the compromise of the HBO Max Reddit account and the subsequent distribution of malware. TechCrunch described how the ClickFix attacks trick users into hacking themselves, detailing the process of copying and pasting commands into system terminals. PC Mag also highlighted the hijacking of the HBO Max account as a method for spreading malware, noting the incident underscores the increasing use of ClickFix-style attacks.

Centre

1 rated outlet

  • The centre-rated report from BleepingComputer focused on the technical details of the attack, identifying the number of malicious advertisements launched (108) and the duration (about 48 hours). It named the security researchers involved, Hudson Rock and ADAMnetworks, and linked the campaign to a larger operation called PasteSwitch. The report also detailed various malware families and attack chains used on both Windows and macOS systems.

Right

0 rated outlets

No outlet rated right has run this story so far. We are still checking, and will say plainly if that does not change.

Questions about this coverage

How did the left and right cover HBO Max Reddit account hijacked to push malware?
Of the 3 outlets on this story carrying a published leaning rating, 67% are rated left, 33% are rated centre, 0% are rated right. Those percentages are shares of the rated outlets, not of every outlet that ran it, which was 13. The sections above set out what each side emphasised, in its own terms.
Is HBO Max Reddit account hijacked to push malware left or right?
Too few of the outlets on this story carry a published leaning rating to say. 3 of them do, and this site does not characterise a field under 12: at that size one newsroom filing moves the share by ten points. The percentages above are the count as it stands.
Is the coverage of HBO Max Reddit account hijacked to push malware biased?
HBO Max Reddit account hijacked to push malware is one event reported by 13 outlets, and this page does not rate the story as biased or unbiased. What it publishes is the spread: which outlets ran it, where named rating organisations place each of them on the spectrum, and what each side chose to lead with. A leaning rating describes an outlet's record over time, not this article, and the two should not be run together.
Which outlets covered HBO Max Reddit account hijacked to push malware?
13 that we know of, every one of them listed further up this page with a link to its own report and to what we hold on the publisher. Nothing here is a summary of somebody else's summary: the outlets are named so the original reporting can be read.
What happened when hackers compromised the HBO Max Reddit account?
Hackers gained control of the official HBO Max Reddit account and used it to post 108 malicious advertisements over approximately 48 hours. These ads were designed to trick users into infecting their computers with information-stealing malware using a technique called ClickFix.
How does the ClickFix attack work?
ClickFix attacks use social engineering to trick users into copying and pasting commands into their operating system's terminal or command prompt. This action installs malware, often information-stealing types, and can bypass some security software because the user initiates the command execution.
Which devices were targeted by the malware?
The malicious advertisements distributed via the compromised HBO Max Reddit account targeted both Windows and macOS devices. The malware installed was designed to steal information from these systems.

Read it at the source

13 outlets, grouped by the leaning a published rating gives them. Every headline links to the original; an underlined outlet name opens our profile of that publisher.

Left

2

Centre

1

Right

0

No outlet in this group ran the story.

Not rated

10
Show 2 more

How did this read?

About the coverage, not about the story. We do not ask whether you agree with what happened — we have no honest use for that answer.

HBO Max Reddit Hacked | MediaBias News