bleeping-computer · Crawled Sep 15, 2026

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

7 IoCs
Read original article ↗

AI Summary

Hackers hijacked HBO Max's verified Reddit account (u/hbomax) to distribute malicious advertisements as part of a campaign dubbed PasteSwitch. These ads used ClickFix social engineering tactics, tricking users into pasting malicious commands into Windows Run, PowerShell, or macOS Terminal under the guise of installing legitimate software or fixing errors. The attack distributed information-stealing malware such as MacSync and AMOS helper on macOS, and PowerShell-based payloads on Windows, including memory-resident Amatera Stealer. Attackers used domains like hbomaxx[.]us and infrastructure including ember-bridge[.]com to deliver payloads and rotate between campaigns targeting both general users and developers.

AI-extracted · verify before operational use

Indicators of Compromise 7 extracted

Type Value Detail
Domain hbomaxx[.]us Details →
Domain ember-bridge[.]com Details →
Domain hbomaxx[.]app Details →
Domain codex-craft[.]com Details →
Domain apple[.]clean-disk-guide[.]com Details →
Domain code-desktop[.]com Details →
Domain hbomax-macos[.]com Details →