A surveillance app disguised as a verified HBO Max account, not a rogue advertiser, ran 108 malicious ads through Reddit’s legitimate ad pipeline over roughly 48 hours in September 2026, exposing users on both macOS and Windows to a coordinated malware operation.
The attack did not rely on traditional file downloads. It used a technique called ClickFix, which directed users to a lookalike HBO Max landing page and instructed them to copy an attacker-supplied command, open Terminal or a Windows utility, paste it in, and run it themselves.
“For 48 hours, the verified HBO Max Reddit account was weaponized to blast 108 malicious ads across the platform, running an evasive cross-platform Clickfix operation we called PasteSwitch,” wrote Alon Gal, founder and CTO of Hudson Rock, in a published analysis.
Hudson Rock and ADAMnetworks jointly identified and named the underlying delivery system, PasteSwitch. It reads the visitor’s operating system and campaign context, then routes to the appropriate payload.
On macOS, PasteSwitch deployed information stealers including MacSync, AMOS, and Amatera Stealer, targeting browser credentials, cookies, Apple Notes data, and crypto wallet information. On Windows, stealers and loaders ran directly in memory alongside cryptocurrency clippers that silently redirect transactions to attacker-controlled wallets.
Counterfeit Ledger, Trezor, and Exodus wallet apps were distributed to capture recovery phrases during setup, secretly tracking users‘ crypto activity. Entering a recovery phrase into one of those apps hands complete wallet control to the attacker.
The campaign used five lure categories in total: a fake HBO Max macOS app, AI coding tools, disk cleaners, fake crypto wallets, and other Windows and macOS software offers. External analysis notes that PasteSwitch rotates its control servers through blockchain entries and disguises its traffic by mimicking legitimate security certificates, methods that point to mature, purpose-built infrastructure.
A user in r/cybersecurity flagged the suspicious ads, which drew researcher attention and prompted Reddit to act. A Reddit spokesperson, as reported by TechCrunch, confirmed: “Reddit recently learned that an HBO Max account authorized to run advertisements on Reddit was compromised and used to run ads containing malicious links.” Reddit locked the account and removed the ads.
A verification badge and a legitimate ad pipeline offered no protection once the account credentials were in attacker hands. Coverage differs on whether the accountability rests with Reddit’s ad review processes or HBO Max’s account security practices; how attackers obtained access has not been publicly confirmed.
Security researchers strongly advise against pasting any command from a web page into Terminal or a Windows utility, even when the page appears to belong to a well-known brand. Readers looking for practical guidance on how to stay safe from these and related threats will find actionable defensive tips worth reviewing.




























