$ techbeacon▋
Malware

Hackers Exploit HBO Max Reddit Page to Distribute ClickFix Malware

Hackers Exploit HBO Max Reddit Page to Distribute ClickFix Malware

Security researchers have confirmed that the official Reddit account for HBO Max was taken over by unknown threat actors, who used the compromised profile to serve malicious advertisements that trigger ClickFix infections on both Windows and macOS computers.

The breach came to light after users reported suspicious ads appearing on a Reddit post linked to the HBO Max account. Analysts traced the payload back to a ClickFix campaign, a known malicious advertising technique that injects code into legitimate ad networks and redirects victims to download information‑stealing malware.

ClickFix attacks typically exploit browser vulnerabilities or use social engineering to convince users to run a disguised installer. Once executed, the malware harvests credentials, browser data, and other personal information, then transmits it to remote command‑and‑control servers. The recent campaign appears to target a broad audience, affecting desktop users of both major operating systems.

Official brand accounts on platforms such as Reddit are attractive to cybercriminals because they carry inherent trust. Followers often assume that links and content posted by a verified account are safe, making them more likely to engage with embedded ads. In this case, the attackers leveraged the HBO Max handle to gain visibility within a community of streaming‑service fans, amplifying the reach of the malicious ads.

While HBO Max and Reddit have not released detailed statements, the incident underscores the need for heightened vigilance when interacting with branded content online. Security experts advise users to avoid clicking on advertisements, especially those that prompt downloads, keep operating systems and software patched, and employ reputable anti‑malware solutions. Both platforms are expected to review their account security protocols and ad‑serving processes to prevent similar compromises.

The investigation remains ongoing, with law‑enforcement agencies and cybersecurity firms working to identify the perpetrators and dismantle the infrastructure behind the ClickFix operation. As the threat landscape evolves, incidents like this highlight the importance of robust digital hygiene and rapid response mechanisms for both users and organizations.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related