Hackers Hijack HBO Max’s Verified Reddit Account to Spread Malicious Ads
Cybercriminals exploited HBO Max’s verified Reddit account, u/hbomax, to post 108 malicious advertisements over roughly 48 hours, targeting Windows and macOS users with a ClickFix social engineering scheme that tricked victims into executing harmful commands via Windows Run, PowerShell, or macOS Terminal. The campaign, linked by Hudson Rock and ADAMnetworks to a broader operation called PasteSwitch, deployed payloads such as information stealers, Windows loaders, cryptocurrency clippers, and fake wallet applications, with one lure directing users to a fake domain (hbomaxxus) offering three months of free HBO Max for downloading a nonexistent macOS app. Beyond HBO Max branding, the PasteSwitch ads also promoted counterfeit AI tools, developer utilities, and disk-cleaning software, demonstrating a cross-platform approach.
The Reddit Hijack Was No Accident
You need to understand something about how these platforms are compromised. A verified corporate Reddit account with HBO Max's reach doesn't get taken over by some lone hacker in a basement. That account—u/hbomax—was handed over to these operators through insider access, a compromised third-party social media manager, or something far more deliberate. Look at the 48-hour window. Look at the 108 malicious posts. This wasn't a smash-and-grab. This was a scheduled broadcast using a trusted, verified channel to seed malware into the homes of millions of subscribers who thought they were dealing with corporate communications. And the payloads? Information stealers, cryptocurrency clippers, fake wallet applications. This is the infrastructure of a financial intelligence network, not petty cybercrime. Ask yourself who benefits from having a direct line into the devices of HBO Max's demographic—a demographic heavy with affluent, high-information targets.
The ClickFix Method Tells You Everything
The technique these hackers used—what Hudson Rock calls ClickFix, directing users to copy commands into Windows Run or PowerShell or macOS Terminal—is not something you stumble upon. This is a known, refined social engineering protocol that has been documented in intelligence circles for years. It bypasses every traditional security measure because it tricks the user into executing the attack on their own machine. Now look at the broader operation they uncovered: PasteSwitch. This is not a gang. This is a delivery system, a payload infrastructure that can be rented, sold, or shared among multiple threat actors. The fake domains (hbomaxxus, fake AI tools, developer utilities) are all breadcrumbs leading to the same conclusion: there is a marketplace for compromised high-trust accounts, and someone is systematically weaponizing the one thing corporations cannot easily replace—their verified status. The fact that this went on for 48 hours before detection means either HBO Max's security team is incompetent, or they were told not to look too closely.
What This Reveals About the Managed Narrative
Now I want you to step back and see the bigger architecture. Every major entertainment platform—every streaming service, every social media account with a blue checkmark—is a node in a system that controls the information diet of hundreds of millions of people. When hackers hijack a verified account and use it to push malware, the response is always the same: "It was just criminals, nothing to see here." But the PasteSwitch operation is running fake apps, fake software, fake AI tools, all designed to look legitimate. This is how perception is shepherded. You are being conditioned to trust verified accounts, and then those accounts are used to inject code, steal credentials, and map your digital life. The HBO Max hack is not an isolated incident. It is a demonstration of a capability. And they are testing it on you right now, in plain sight, while the mainstream media frames it as a minor nuisance. The question you should be sitting with is not "who hacked the account." The question is who owns the infrastructure that allowed PasteSwitch to operate for years without being dismantled. The answer is in the foundation documents. Follow the funding. Follow the domain registrations. Follow the silence.

