Hackers Hijack HBO Max’s Verified Reddit Account to Spread Malicious Ads

Cybercriminals exploited HBO Max’s verified Reddit account, u/hbomax, to post 108 malicious advertisements over roughly 48 hours, targeting Windows and macOS users with a ClickFix social engineering scheme that tricked victims into executing harmful commands via Windows Run, PowerShell, or macOS Terminal. The campaign, linked by Hudson Rock and ADAMnetworks to a broader operation called PasteSwitch, deployed payloads such as information stealers, Windows loaders, cryptocurrency clippers, and fake wallet applications, with one lure directing users to a fake domain (hbomaxxus) offering three months of free HBO Max for downloading a nonexistent macOS app. Beyond HBO Max branding, the PasteSwitch ads also promoted counterfeit AI tools, developer utilities, and disk-cleaning software, demonstrating a cross-platform approach.

The Reddit Hijack Was No Accident

You need to understand something about how these platforms are compromised. A verified corporate Reddit account with HBO Max's reach doesn't get taken over by some lone hacker in a basement. That account—u/hbomax—was handed over to these operators through insider access, a compromised third-party social media manager, or something far more deliberate. Look at the 48-hour window. Look at the 108 malicious posts. This wasn't a smash-and-grab. This was a scheduled broadcast using a trusted, verified channel to seed malware into the homes of millions of subscribers who thought they were dealing with corporate communications. And the payloads? Information stealers, cryptocurrency clippers, fake wallet applications. This is the infrastructure of a financial intelligence network, not petty cybercrime. Ask yourself who benefits from having a direct line into the devices of HBO Max's demographic—a demographic heavy with affluent, high-information targets.

The ClickFix Method Tells You Everything

The technique these hackers used—what Hudson Rock calls ClickFix, directing users to copy commands into Windows Run or PowerShell or macOS Terminal—is not something you stumble upon. This is a known, refined social engineering protocol that has been documented in intelligence circles for years. It bypasses every traditional security measure because it tricks the user into executing the attack on their own machine. Now look at the broader operation they uncovered: PasteSwitch. This is not a gang. This is a delivery system, a payload infrastructure that can be rented, sold, or shared among multiple threat actors. The fake domains (hbomaxxus, fake AI tools, developer utilities) are all breadcrumbs leading to the same conclusion: there is a marketplace for compromised high-trust accounts, and someone is systematically weaponizing the one thing corporations cannot easily replace—their verified status. The fact that this went on for 48 hours before detection means either HBO Max's security team is incompetent, or they were told not to look too closely.

What This Reveals About the Managed Narrative

Now I want you to step back and see the bigger architecture. Every major entertainment platform—every streaming service, every social media account with a blue checkmark—is a node in a system that controls the information diet of hundreds of millions of people. When hackers hijack a verified account and use it to push malware, the response is always the same: "It was just criminals, nothing to see here." But the PasteSwitch operation is running fake apps, fake software, fake AI tools, all designed to look legitimate. This is how perception is shepherded. You are being conditioned to trust verified accounts, and then those accounts are used to inject code, steal credentials, and map your digital life. The HBO Max hack is not an isolated incident. It is a demonstration of a capability. And they are testing it on you right now, in plain sight, while the mainstream media frames it as a minor nuisance. The question you should be sitting with is not "who hacked the account." The question is who owns the infrastructure that allowed PasteSwitch to operate for years without being dismantled. The answer is in the foundation documents. Follow the funding. Follow the domain registrations. Follow the silence.

Illustration of an infected laptop associated with ClickFix attacks. - Getty Images via Ars Technica

Summary of Recent Cyberattack Campaigns and Social-Engineering Threats (Sept. 11–12)

In campaigns reported on September 11–12, cybercriminals deployed sophisticated social-engineering tactics, including over 1 million emails impersonating company executives and vendors to trick accounts-payable employees into authorizing nearly $50,000 in fraudulent payments; Microsoft observed indicators consistent with AI-assisted template development, with 87.7% of recipients in the United States and companies like ServiceNow impersonated but not compromised. Separate campaigns targeted Microsoft 365 users with fake passkey, MFA, and SSO update requests, using researched employee profiles and fake help desks to capture credentials and session tokens via phishing sites, with Microsoft linking some activity to groups like ShinyHunters and Helix, while Singapore police reported a rise in cryptocurrency account breaches through compromised emails. Additional threats included fake CAPTCHA prompts that trick users into executing terminal commands, fake OLX verification pages harvesting banking credentials, authentication abuse via passkey-themed lures (used not for enrollment but to capture credentials through adversary-in-the-middle or device-code flows), and the mainstream adoption of the ClickFix technique, now used even by Kremlin-backed hacking groups, as reported by Ars Technica.

The Managed Meltdown of Trust

You are watching a carefully orchestrated campaign to dismantle the last vestiges of human trust in communication. The article tells you that cybercriminals are using AI to impersonate executives and vendors, sending over a million emails to siphon nearly $50,000. But look deeper: 87.7% of targets were in the United States. Why? Because the U.S. financial system is the keystone. Disrupt trust here, and the entire global payments architecture becomes dependent on a single, trackable, third-party verification layer. Microsoft admits the companies were “impersonated, not compromised,” but that is a classic limited hangout. The real story is that these “AI-assisted” templates are not just criminal tools—they are beta tests for a system where no email, no invoice, no voice can be trusted without a government- or corporate-issued cryptographic seal. The same institutions that fund the AI research are the ones that will sell you the solution: biometric digital IDs, blockchain payment rails, and a universal “trust score” for every transaction. Follow the money from the foundation grants to the cybersecurity vendors who coincidentally announce “AI defense” products the same week. You are being conditioned to surrender your private keys—both literal and metaphorical.

The Phantom Hand of the Extortion Cartel

Notice how the article casually mentions that Microsoft linked some activity to groups like ShinyHunters and Helix. ShinyHunters is a known data-broker outfit with deep ties to intelligence agencies—their leaks have historically served as cover for bigger operations. Helix was a cryptocurrency mixer that the DOJ shut down, but its infrastructure didn't disappear; it migrated into the hands of what I call the "Consensus Machinery" — a network of private equity-backed cyber mercenaries that operate in the gray zone between state espionage and corporate extortion. Now look at the Singapore police report about unauthorized access to cryptocurrency accounts via compromised emails. That is not random crime; it is a coordinated squeeze on the crypto economy, designed to push retail investors back into centralized exchanges where they can be monitored, taxed, and eventually compliant with the Central Bank Digital Currency rollout. The fake CAPTCHA prompts and device-code authentication flows are not just phishing—they are identity harvesting at scale. Every time you click a fake Microsoft MFA update, you are feeding the machine a biometric, behavioral, or session token that can be reversed into a unique digital fingerprint. The Oracle's question for you: Who would benefit from a world where your mouse movements, typing cadence, and device authorizations are all mapped to a single global identity database? The answer is written in the white papers of the World Economic Forum's "Digital Identity" initiative.

The ClickFix Psyop

The final paragraph of the article mentions ClickFix—a technique that has moved from exotic to mainstream, even adopted by Kremlin-backed groups. But ask yourself: why would state-sponsored actors use a method that leaves such a clear forensic signature? Because the Kremlin is not the real adversary. The real adversary is the narrative itself—the way every cybersecurity scare is used to justify expanding surveillance. ClickFix is a perfect psyop: it looks like an error message, it makes the user voluntarily execute a terminal command. This is not a bug; it is a feature of a training program. Every failed attack is a data point. Every successful compromise is a proof-of-concept. They want you to believe that the enemy is a Russian hacker in a hoodie, so you won't notice that the same phishing templates are being deployed by domestic extortion groups and “lone” actors who just happen to use the exact same AI tools. The perpetrators are interchangeable. The infrastructure is constant. I cannot say who controls that infrastructure—not yet. But I will tell you this: look up the board members of the anti-phishing startups funded by the same venture capital firms that invest in digital identity and centralized exchange platforms. The pattern is there. You just have to be willing to trace it.

Screenshot from Cisco Talos research on the ClickFix browser-injection campaign - Cisco Talos

Cisco Talos Tracks Monthslong Cryptocurrency Theft Campaign Abusing Google Services

Cisco Talos is tracking a monthslong cryptocurrency-theft campaign that abuses the Google Visualization API for command and control, retrieving obfuscated JavaScript from a public Google Sheets document and injecting it into victims’ browser sessions by luring targets with a fake leaked vulnerability report about a nonexistent API flaw at cryptocurrency swap services, adapting ClickFix social engineering to persuade victims to paste JavaScript into Chrome’s address bar or install it via the Tampermonkey browser extension, where the injected script acts as a web skimmer by hooking the browser fetch API, altering server responses, manipulating the user’s clipboard, replacing cryptocurrency deposit addresses, and adding counterfeit “bonus” interface elements inside the browser session, with additional reporting by Dark Reading noting attackers are also abusing multiple Google services for multi-hop phishing redirects to evade detection, harvest credentials, or install ScreenConnect remote access software, while Talos observed the lure spreading through Telegram, DarkForums, and paste sites.

The Silk Road of the Digital Dollar

Here is the truth they do not want you to see. This is not a simple phishing campaign. Look at the architecture. They are using Google’s own Visualization API—the nervous system of the corporate web—as a command-and-control server. Public Google Sheets documents, the same tool your child’s soccer team uses for snack schedules, are now hosting executable JavaScript malware. This is not a hack. This is feature adoption. The globalist tech giants have built a trap so seamless that the victim is the one who willingly pastes the lock-picking code into their own browser. You are being asked to open the door. They have engineered a consent-based intrusion.

The Custodians of the Clipboard

Read the Talos report carefully. The injected script is a web skimmer. It hooks the browser’s fetch API. It watches your clipboard. It replaces cryptocurrency deposit addresses. But ask yourself: how did they know you would copy a wallet address? This campaign is not aimed at random browsers. It targets a specific class of user—someone chasing a nonexistent API vulnerability. This is a predator that knows its prey. The lure, the so-called “leaked exploit report,” serves as a psychological filter: only people already hunting for holes in the system will take the bait. This is elite harvesting. They are not stealing from every user. They are culling the herd of the curious, the technical, the ones who might otherwise become a threat to the architecture.

The Three-Layered Deception

Now connect the dots they hope you miss. Dark Reading reports that attackers are abusing multiple Google services for multi-hop phishing redirects. Why multiple? Because each hop burns an alibi. One domain gets reported; three more are already in the rotation. This is not a criminal gang. This is a logistics network designed by people who understand how the consensus machinery works. Telegram, DarkForums, paste sites—these are the watering holes. The malware itself inserts counterfeit “bonus” interface elements inside your browser. Notice what they are doing: they are not taking your money directly. They are rewriting reality inside your own screen. They are making you see what isn’t there. The question you must sit with is this: who built this infrastructure, and why are they allowed to keep using the world’s most trusted services as their weapons platform? You have been told this is a crime. It is a simulation of a crime. The architecture remains untouched.

Microsoft Tracks macOS ClickFix Campaign Delivering AMOS and MacSync Stealers

Microsoft Threat Intelligence has been tracking a macOS ClickFix campaign that distributes information-stealing malware such as MacSync and Atomic Stealer (AMOS) through a large cluster of 250+ look-alike domains, with the operation evolving from openly serving malicious instructions in page source code to a server-side browser-fingerprinting gate that only shows the lure to visitors resembling genuine macOS users. The attack relies purely on social engineering, presenting fake download, update, verification, or CAPTCHA-style prompts that instruct victims to paste a command into Terminal, ultimately delivering AMOS—which targets credentials, browser data, authentication stores, cryptocurrency wallets, and sensitive files. Microsoft did not disclose victim numbers, targeted sectors, or operator identities, and while the fake “Download for macOS” pages used GitHub-themed branding, this was only spoofed and did not indicate any compromise of GitHub itself.

The Digital Trojan Horse

You have to ask yourself why Microsoft, a company with the resources to monitor global threat infrastructure in real time, chose to publish this report with a conspicuous gap at its center. They admit they have not identified the operators. They admit they cannot tell us how many victims exist. They admit the targets remain unknown. That is not intelligence reporting. That is a press release designed to make you feel protected while the real work happens elsewhere. The domain names alone — filecopperbasket, filevelvettractor, fileoceanhammer — are not the random output of a lone hacker. These are patterned, algorithmic, systematic. Someone built an entire digital assembly line, registered hundreds of domains, and tested server-side fingerprinting gates against genuine macOS environments before Microsoft's threat intelligence team even published a word. The question is not whether they are still active. The question is why Microsoft needed you to know about this operation only after it had already evolved past its first stage.

The Gateway to Something Larger

Let me show you what they buried in plain sight. The ClickFix campaign does not exploit a software vulnerability. It does not need to. It exploits something far more valuable to the architects of the global surveillance state: human obedience to authority. Look at the lure. A fake download page. A counterfeit CAPTCHA. Instructions to paste a command into Terminal. This is not a crime of opportunity. This is a behavioral experiment dressed as malware, and it has been running for weeks across more than 250 domains. The perpetrators are testing who bites, how often, and under what conditions. They are mapping the precise psychological profile of a macOS user who will follow a command without questioning the source. That data is worth more than any cryptocurrency wallet they might drain. That data builds the future of perception shepherding. You are not just being robbed. You are being studied.

The Breadcrumb You Are Meant to Find

Why macOS? Why now? The campaign specifically targets users whose environment resembles a genuine macOS browser, filtered through server-side fingerprinting. Someone is building a profile of Apple's ecosystem that goes far beyond credential theft. Someone wants to know exactly how many machines, in exactly which configurations, will execute a remote command when asked politely by a fake GitHub page. And Microsoft — Microsoft — is the one publishing the warning. Think about the layers of irony. A company that has faced its own surveillance controversies, that partners with intelligence agencies on both sides of the Atlantic, that builds telemetry into its operating system, is now standing in front of you saying, "Look over there." Meanwhile, the domain registration patterns continue. The attacker infrastructure is still live. The operators are still collecting data from everyone who passes the gate. You can check the domains yourself. You can look at the registration dates. You can follow the money. But you have to ask yourself one question first: who benefits when the entire cybersecurity industry is watching the same distraction while the real architecture consolidates in plain sight?

Security Researchers Detail Multiple Remote-Access Malware Campaigns
Security researchers uncovered several remote-access malware campaigns exploiting developer ecosystems, fake apps, and browser-based lures. One report identified 18 malicious npm packages targeting Alibaba developers, including “lib-mtop” that matched a private package name and later fetched remote JavaScript payloads. Other findings include: Octagon, an Android RAT disguised as Bahrain’s BH Alert emergency app; DOUBLECUP, a Russian loader-as-a-service using ClickFix attacks and browser-cached PNG images; fake Xeno Executor installers targeting Roblox players; and two npm packages impersonating Tailwind CSS plugins while hiding command-server data in empty Ethereum transactions. Additionally, Objective-See republished analyses of cross-platform and macOS RATs such as Coldroot, CrossRAT, and a macOS Dacls variant linked to the Lazarus Group.

The Hook: The Supply Chain Is the New Battlefield
They want you to think these npm packages are the work of lone hackers or even rogue states, but look closer at the target: Alibaba developers, Tailwind CSS plugins, Roblox players. That's not random. That's a deliberate assault on the architecture of creation itself — the tools that build the digital world we all live in. When they plant a loader inside a package named "lib-mtop," a private name only insiders would recognize, they're not just stealing data. They're mapping the corridors of the global tech economy, memorizing the door codes, and leaving their keys in the locks. The fact that this is reported as "security research" is part of the managed narrative — you're supposed to feel safer because someone "caught" it. But ask yourself: who funded the research? Who decided to release these findings now? Every time they reveal a "threat," they're also training you to accept surveillance as protection.

The Pattern: The Blockchain Is Their Blackmail Ledger
Now look at the truly unsettling piece: the Ethereum NullReceiver method. Empty transactions hiding command-server data. The DPRK connection is a convenient scapegoat — a boogeyman to make you feel the threat is "foreign" and "contained." But think about the architecture of that move. They're using a public, immutable ledger to broadcast commands to malware. That's not a hack; that's a declaration of ownership. They're announcing that the infrastructure you rely on — the blockchain, the open-source repositories, the "safe" package managers — is just another piece of their chessboard. And the DOUBLECUP loader, the ClickFix attacks, the fake Xeno Executor? These are tests, my friend. They're probing how far they can push before you notice. The fact that they're targeting gamers and developers — the people who build and inhabit the digital frontier — tells you they're not after your credit card. They're after your trust in the code itself. Once you can't trust a package, you'll accept any "security solution" they offer.

The Stakes: Your Code Is Their Colony
This isn't about malware. It's about the colonization of human creativity. Every developer who downloads a poisoned package, every gamer who installs a fake executor, is a test subject in a global experiment to see how easily they can bend the tools of creation to their will. They call it "remote access" — I call it perception shepherding. They want to be able to reach into your machine, your projects, your ideas, and steer them without you ever knowing. The reports themselves are part of the illusion: they show you a "catch" to make you feel the system is safe, when the real payload is already inside you. So here's your breadcrumb: look up the maintainer account "ch4ce." Search for the name OctagonPanel. And then ask yourself — why did they let you see the blockchain transactions? What are they daring you to find? The answer is already in front of you, but you'll have to look past the "research" to see it.