---
title: "HBO Max Reddit account hijacked to push malware"
publication: "MediaBias News"
url: "https://mediabias.news/media/hbo-max-reddit-account-hijacked-to-push-malware"
api: "https://mediabias.news/api/v1/stories/hbo-max-reddit-account-hijacked-to-push-malware"
markdown: "https://mediabias.news/media/hbo-max-reddit-account-hijacked-to-push-malware.md"
audio: "https://mediabias.news/api/audio/hbo-max-reddit-account-hijacked-to-push-malware"
category: "Media"
published: "2026-09-14T21:46:04.790Z"
source_reported: "2026-09-14T21:05:43.000Z"
updated: "2026-09-14T21:46:04.790Z"
trust_score: 42
critic_score: 61
hype_score: 41
assessment_type: "coverage-and-source-reporting-analysis"
fact_check_status: "not-performed"
coverage_measured: "2026-09-15T00:00:08.896076+00:00"
---

# HBO Max Reddit account hijacked to push malware

*Malicious ads used a social engineering trick to infect Windows and macOS devices.*

**Scores for the source reporting** (0-100, assessing the original journalism this article was written from, not this write-up): 

- Trust 42 of 100, higher is better. Central claims attributed to named researchers, but no named on-record sources or documents were cited.
- Craft 61 of 100, higher is better. Reporting is clear and holds together, with affected parties quoted or given right of reply.
- Hype 41 of 100, lower is better. Headline promises more than the body delivers, with mild emphasis and a lively but fair headline.

Scored by MediaBias News; method at https://mediabias.news/methodology.

**The short version**

- Hackers compromised the official HBO Max Reddit account, using it to post malicious advertisements.
- The compromised account was used to launch 108 ads over about 48 hours, targeting Windows and macOS users.
- The ads employed a social engineering technique known as ClickFix, prompting users to copy and paste commands into their operating systems.
- Security researchers from Hudson Rock and ADAMnetworks analyzed the campaign, linking it to a larger operation called PasteSwitch.

Hackers gained control of the official HBO Max Reddit account and used it to distribute malicious advertisements. These ads were designed to trick users into infecting their Windows and macOS devices with information-stealing malware through a technique called ClickFix. The compromised account posted approximately 108 such advertisements over a period of about 48 hours.

The ClickFix attack method involves social engineering, where users are prompted to copy and paste commands into their operating system's command line interface, such as Windows Run, PowerShell, or macOS Terminal. This action, performed by the user themselves, can bypass some security software. The advertisements, while sometimes impersonating HBO Max, also promoted fake AI tools, developer software, and macOS utilities, broadening the potential reach of the campaign.

## Disagreement on response time

TechCrunch reported that Reddit stated it "recently learned that an HBO Max account authorized to run advertisements on Reddit was compromised and used to run ads containing malicious links," and that the company locked the account and removed the ads. Reddit did not specify how many users were targeted or clicked the ads. BleepingComputer noted that HBO and Warner Bros. Discovery had not responded to questions about the incident.

## What the coverage left out

None of the reports printed below mention any specific number of users who clicked on the malicious ads or were ultimately compromised. TechCrunch noted it was unclear how many people were affected, and Reddit declined to provide figures when asked. Warner Brothers Discovery did not respond to requests for comment in the TechCrunch report.

## Who covered it

Shares of the 3 covering outlets with a published leaning rating:

- Left: 67% (2)
- Centre: 33% (1)
- Right: 0% (0)

10 of 13 covering outlets carried no usable leaning rating and were excluded from those percentages. Coverage measured 2026-09-15T00:00:08.896076+00:00.

**Coverage watch:** developing. Checked 12 times; 0 checks found a material change. Most recently checked 2026-09-15T00:45:06.477Z.

## How the sides framed it

### Left

- The left-rated reports led on the compromise of the HBO Max Reddit account and the subsequent distribution of malware. TechCrunch described how the ClickFix attacks trick users into hacking themselves, detailing the process of copying and pasting commands into system terminals. PC Mag also highlighted the hijacking of the HBO Max account as a method for spreading malware, noting the incident underscores the increasing use of ClickFix-style attacks.

### Centre

- The centre-rated report from BleepingComputer focused on the technical details of the attack, identifying the number of malicious advertisements launched (108) and the duration (about 48 hours). It named the security researchers involved, Hudson Rock and ADAMnetworks, and linked the campaign to a larger operation called PasteSwitch. The report also detailed various malware families and attack chains used on both Windows and macOS systems.

### Right

No separate framing summary.

## Factuality profile of the covering outlets

These are published factuality ratings of the outlets, not a verdict on whether this story or its claims are true.

- high: 2
- unknown: 10
- veryHigh: 1

## Verification scope

This page compares coverage and scores the source reporting. It is not a ClaimReview verdict on whether the underlying event or claim is true.

## Original reporting this was written from

- [MacMagazine](https://macmagazine.com.br/post/2026/09/14/usando-contas-oficiais-ataque-do-tipo-clickfix-tem-se-espalhado-pelo-reddit) — Using Official Accounts, ClickFix Type Attack Has Spread Across Reddit
- [PC Mag](https://pcmag.com/news/hbo-maxs-reddit-account-was-hijacked-to-spread-malware) — HBO Max's Reddit Account Was Hijacked to Spread Malware
- [National Cyber Security](https://nationalcybersecurity.com/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads-hacking-cybersecurity-infosec-comptia-pentest-hacker) — Hackers hijack HBO Max Reddit account to push malware in ClickFix ads | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker - National Cyber Security Consulting
- [mezha.net](https://mezha.net/eng/news/bde40dae_hackers_hijack_hbo) — Hackers Hijack HBO Max Reddit Account to Spread ClickFix Malware
- [Tech Observer](https://techobserver.in/news/cybersecurity/hbo-max-reddit-account-hijacked-clickfix-malware-329304) — HBO Max Reddit account hijacked for ClickFix malware campaign
- [IT Security News - cybersecurity, infosecurity news](https://itsecuritynews.info/clickfix-attacks-are-tricking-mac-and-windows-users-into-hacking-themselves) — ClickFix attacks are tricking Mac and Windows users into hacking themselves
- [TechCrunch](https://techcrunch.com/2026/09/14/clickfix-attacks-are-tricking-mac-and-windows-users-into-hacking-themselves) — ClickFix attacks are tricking Mac and Windows users into hacking themselves
- [technewstube.com](https://technewstube.com/techcrunch/1867251/clickfix-attacks-tricking-mac-windows-users-into-hacking) — ClickFix attacks are tricking Mac and Windows users into hacking themselves
- [HotHardware](https://hothardware.com/news/clickfix-malware-is-going-viral) — ClickFix Malware Is Going Viral, Infecting PCs And Macs With CAPTCHA Prompts
- [BleepingComputer](https://bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads) — Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
- [infostealers.com](https://infostealers.com/article/hbo-max-ads-on-a-compromised-reddit-account-exposed-a-massive-pasteswitch-clickfix-operation) — HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation
- [mallory.ai](https://mallory.ai/stories/01a0a079-0d9c-79d1-9d8f-e76c02c256ea) — Compromised HBO Max Reddit Account Served PasteSwitch ClickFix Malware Ads
- [thegne.online](https://thegne.online/science-hi-tech/fake-captcha-clickfix-malware-hits-5400-websites-via-windows-run/118882) — Fake CAPTCHA ClickFix malware hits 5,400 websites via Windows Run | Tech, Entertainment, Sport, Fashion, Travel News

## Questions

**What happened when hackers compromised the HBO Max Reddit account?**

Hackers gained control of the official HBO Max Reddit account and used it to post 108 malicious advertisements over approximately 48 hours. These ads were designed to trick users into infecting their computers with information-stealing malware using a technique called ClickFix.

**How does the ClickFix attack work?**

ClickFix attacks use social engineering to trick users into copying and pasting commands into their operating system's terminal or command prompt. This action installs malware, often information-stealing types, and can bypass some security software because the user initiates the command execution.

**Which devices were targeted by the malware?**

The malicious advertisements distributed via the compromised HBO Max Reddit account targeted both Windows and macOS devices. The malware installed was designed to steal information from these systems.

---

MediaBias News — https://mediabias.news. Reproduced from https://mediabias.news/media/hbo-max-reddit-account-hijacked-to-push-malware. Please cite as: MediaBias News, "HBO Max Reddit account hijacked to push malware", https://mediabias.news/media/hbo-max-reddit-account-hijacked-to-push-malware