HACKERS HIJACK HBO MAX REDDIT ACCOUNT TO SPREAD CLICKFIX MALWARE

Hackers reportedly compromised HBO Max’s verified Reddit account and used it to distribute malicious advertisements designed to infect Windows and macOS devices with information-stealing malware. Researchers from Hudson Rock and ADAMnetworks said the hijacked u/hbomax account launched 108 malicious ads over roughly 48 hours.

The campaign relied on a social engineering technique known as ClickFix. Instead of directly downloading malware, ClickFix attempts to convince victims to copy and execute malicious commands through tools such as Windows Run, PowerShell, or macOS Terminal. Attackers often disguise these instructions as CAPTCHA verification steps, software installations, or fixes for fake computer errors.

This approach can be particularly dangerous because the victim executes the commands using legitimate operating-system utilities. That can make some stages of the attack appear more trustworthy while potentially helping malicious activity evade protections focused on traditional browser-based malware downloads.

Researchers found that the malicious ads did not exclusively impersonate HBO Max. Some promoted fake AI applications, developer tools, and macOS utilities in an effort to attract different types of users. The campaign reportedly came to light after a Reddit user noticed an advertisement from HBO Max’s verified account promoting what appeared to be a legitimate HBO Max application for macOS.

The incident highlights why users should never paste unfamiliar commands into PowerShell, Terminal, Windows Run, or other system tools simply because a website or advertisement tells them to. CAPTCHA challenges and legitimate software installers generally should not require users to manually execute suspicious commands to continue.

Leave a Comment

Your email address will not be published. Required fields are marked *