Hackers have used a trusted Reddit identity to turn advertisements into a malware delivery channel. A compromised, verified HBO Max account, u/hbomax, published 108 malicious ClickFix ads over 48 hours, sending people toward fake software pages.
The campaign did not rely on a software vulnerability. It relied on persuasion: a polished page claimed to offer a native HBO Max app for macOS, then told visitors to copy a command into Terminal. That handed the final execution step to the victim.
HudsonRock researchers, working with independent researcher Kirk from ADAMnetworks, identified the activity as part of a wider cross-platform operation they call PasteSwitch.
The operation linked fake streaming ads with lures for AI tools, developer utilities and disk-cleaning software. The potential impact goes well beyond an unwanted ad.
HudsonRock said in a report shared with Cyber Security News (CSN) that PasteSwitch can deliver credential stealers, Windows loaders and cryptocurrency-address clippers, risking browser data, saved passwords and digital assets.

It also gives attackers a reusable framework that can swap brands, lures and payloads while retaining the same underlying core delivery methods. Reddit paused the ads and began an investigation, but a verified account is not proof that a download is safe.
Hackers Hijack HBO Max Reddit Account
The suspicious advertising was first reported after a Reddit user encountered an official-looking ad from u/hbomax.
It promoted a standalone macOS application that does not exist. The linked page copied HBO Max branding before presenting its trap.
ClickFix works by replacing a normal install with a manual action. After a visitor pressed Download, the page displayed an overlay that asked them to copy and paste a command. As recent ClickFix malware attacks demonstrate, this approach makes users run attacker code.
![The fraudulent landing page hosted at hbomaxx[.]us (Source - HudsonRock)](https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5HlYxmLlt71kVy8vQ7GCnhmZykzWse5lOFPnqxGDbKqsE3SC3FdutIhP0dy08gqEI2zrf9oPN9bFyjzmupN0t713fc6l4VaAy8vlLgHUKA6Ul4YTyTnj1px8Pec_3IlmhoqXEETu1hXE18MZ7iAK_ZZulwSwHfMvIzhUtGng2rUOYfrQOFbPUIZkPuoE/s1600/The%20fraudulent%20landing%20page%20hosted%20at%20hbomaxx%5B.%5Dus%20%28Source%20-%20HudsonRock%29.webp?w=1260&ssl=1)
The operators moved quickly as domains were detected or blocked. Ads included 40 streaming-themed placements using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15 tied to apple.clean-disk-guide[.]com, 11 for code-desktop[.]com and six for hbomax-macos[.]com.
The compromised account gave the actors a trusted advertising identity for two days. Convincing branding can lower caution around ads.
PasteSwitch Expands Across Platforms
The researchers found a delivery system that changes its path depending on the visitor and campaign. On macOS, the pasted command can use curl and zsh to fetch MacSync, AMOS-related helpers or fake wallet apps.
They can collect credentials, Telegram data, Apple Notes and macOS passwords; fake wallets seek recovery phrases. Windows visitors can receive a separate InstallFix route that uses mshta and PowerShell.
A disguised MP3/HTA file can create a scheduled task, launch 32-bit PowerShell and disable the Antimalware Scan Interface before subsequent code runs.
Amatera can then load into memory, evading conventional file-based checks. The report also described deceptive TLS traffic that connected to an attacker-controlled IP while presenting facebook.com as its visible server name, potentially misleading simple network logs.
The operation’s clipper branch adds another risk. AnimateClipper and ZigClipper watch the clipboard and replace copied cryptocurrency addresses with an attacker’s address.

Their controllers can retrieve a current command-and-control domain from Binance Smart Chain contracts, letting actors rotate infrastructure.
Defenders should block the listed infrastructure, inspect alerts involving copied commands and investigate unexpected Terminal, Run-dialog, mshta or PowerShell activity.
Never paste commands from ads, pop-ups or web pages. Mac-focused ClickFix delivery chains show why verification and installer commands deserve caution.
Organizations should also review whether staff saw the ads or visited the associated sites, reset exposed credentials if exposure is suspected and monitor for unusual browser-data collection.
Network teams can correlate direct IP connections with unusual SNI, DNS and certificate behavior. Earlier reporting on blockchain C2 malware campaigns also illustrates why blockchain-based control channels need attention during an investigation.
The HBO Max incident is a reminder that malvertising can borrow the reputation of a legitimate account, then turn a routine click into an infection. Treat copy-and-paste install prompts as warnings and validate software through official channels.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP address | 45.94.47[.]204:80 | AMOS helper enrollment, task polling and acknowledgement server |
| IP address | 77.91.65[.]13:443 | Amatera direct-to-IP TLS command-and-control server using facebook[.]com SNI |
| IP address | 165.22.199[.]85 | September macOS telemetry and /contact data exfiltration |
| IP address | 164.90.161[.]147:80 | September macOS post-execution HTTP contact |
| IP address | 92.246.136[.]14 | AMOS helper fallback /contact exfiltration |
| IP address | 62.60.226[.]69 | Shared Nova and macOS-tool cluster provisioning infrastructure |
| IP address | 176.53.159[.]66 | Shared delivery infrastructure associated with TLS and Windows executable activity |
| IP address | 172.236.51[.]169 | Origin observed for storageprofiler[.]com gated lure |
| IP address | 138.124.93[.]32 | AMOS helper /contact exfiltration |
| IP address | 168.100.9[.]122 | AMOS helper /contact exfiltration |
| IP address | 199.217.98[.]33 | AMOS helper /contact exfiltration |
| IP address | 38.244.158[.]103 | AMOS helper /contact exfiltration |
| IP address | 38.244.158[.]56 | AMOS helper /contact exfiltration |
| Domain | filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[.]com | Copied-command lure domains |
| Domain | flutelikelurkerunsinewy[.]com; camaligsalvatrefoils[.]com | Click-tracking domains |
| Domain | press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com | macOS loader-delivery domains |
| Domain | weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com | September macOS telemetry and delivery domains |
| Domain | houstongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com | MacSync delivery and control domains |
| Domain | arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com | AMOS helper and tasking domains |
| Domain | loop-lumen[.]com; umapla[.]com; glrack[.]com | Fake wallet delivery domains |
| Domain | desktop-version[.]com; oakenfjrod[.]ru | Windows staging domains |
| Domain | sic180[.]com; habar55[.]namebright[.]bike | SIC Windows-route domains |
| Domain | crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; codex-craft[.]com; code-desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us | Provisioning-linked lure domains |
| Domain | applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com | Provisioning-neighborhood domains |
| Domain | chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com; hindustanagency[.]com | Teardown and delivery-neighborhood domains |
| Domain | euquiz[.]space | Address-reuse domain |
| Domain | lb[.]propertyfind[.]cc | Smart-contract-resolved command-and-control domain |
| Domain | br[.]hugo-lapp[.]co; carlessclapped[.]com; cf[.]hugo-mapp[.]co; cw[.]hugo-lapp[.]lat; dau[.]hugo-mapp[.]co; dmt[.]unguidedfreewill[.]co; doh[.]hugo-mapp[.]co; ed[.]hugo-lapp[.]lat; en[.]hugo-mapp[.]co; esp[.]hugo-mapp[.]co; fcp[.]unguidedfreewill[.]co; fd-api-irc[.]velqo7[.]co; fd-api-irf[.]velqo7[.]co | C2 history decoded from AnimateClipper and ZigClipper smart-contract transactions |
| URL path / artifact | /dynamic?txd=; /tmp/osalogging.zip; .com.apple.accountsd; /api/join/; /api/tasks/<bot-id> |
MacSync and AMOS helper staging, persistence, enrollment and tasking indicators |
| Smart contract | 0x6936edc505501EBB2F202C985a021a06f1c10C9E | AnimateClipper Binance Smart Chain contract |
| Smart contract | 0x7CC3cFC1Ac007B8c6566fD2C7419b15a75473468 | ZigClipper Binance Smart Chain contract |
| Cryptocurrency wallet | 0x3a35b409af86e79e8945d6a7ffb1dc59b8dbdf46 | Attacker controller address associated with contract updates |
| Smart-contract method | 0x3bc5de30; 0x70a08231; 0x47064d6a | Selectors for getData(), balanceOf() and setData() |
| SHA-256 | eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009 | September macOS artifact |
| SHA-256 | d4150c1c97f047c6edb14767bf1efa8f9e37d63b124f38f27da4ef52d570aac2 | AccountsHelper artifact |
| SHA-256 | f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7; a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287e6a411 | Metadata artifacts |
| SHA-256 | 93d986f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae; e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c | Arkypc loader and helper |
| SHA-256 | f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e; 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4; ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb | Fake Ledger, Trezor and Exodus application artifacts |
| SHA-256 | 5e8ad983129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad; 480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5; 3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92541a24 | InstallFix MP3/HTA, InstallFix /cl and recovered InstallFix artifacts |
| SHA-256 | ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb | Recovered x86 artifact and Amatera PE |
| SHA-256 | 6759c72365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7; 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 | SIC MP3/HTA payload and Talos clipper artifact |
| SHA-256 | 06a3d3bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b; d1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c; ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540; 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505; 249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938; 9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e849cd96 | Houston, Pressureulcerlawyer, Lalandscapelighting, Aidevmaster, Pinescope11 and Dogtrainers MacSync shell stages, plus Trekmesh15 AMOS helper shell stage |
| Cryptocurrency wallet | 0xA1E50DaF64fb2B342A64d848E396700962acC2d0; 1PbWWqgKDBDorh525uecKaGZD21FGSoCeR; 31kwGkJP9xM26cnQJLpe1CH6pjSt4DEDz2; 32Epo1K92Xzo6Hayq1Fmkj21x4fUk7JZT7; bc1qcg5sx6a6evx5ls4gj6nh8d0jtamh89n2y473dr; bc1pqn73hlel3mmnza0kfl2alwkkgkapeeknufgtysll8fs2z4umdf0qpvus9q; ltc1qk437ykzdxms9k9wh5vhd7aalsv0tfx6r39rrtv; LV9AYZKQEg891crnof7PFK6u77noVM4Y45; MG1FerSxboiwjhvU2cv4n34pXz5FpC88p4; TNf4nzc6x6fZrBMLMaZZGV1SbCjShDqbaQ; r9yMnTm4NSzvG9rrwjM2ec8xZgh1cafXH8; cosmos1k5xu6njlc90r92gdwvtfjh826jduw7ptmry0q8; UQDvDUxFShoWWbHougyHjr0tFz3E38fX8e0bnTUpya-P0mXW; DH9W9S6mSSBsGeiSstgsGdiREZupQbZf9C | AnimateClipper and ZigClipper cryptocurrency address-replacement targets |
| Cryptocurrency wallet | addr1q96640zpnccyktlmjqnzqnypwugva9g9dcuk0f5jt9mjz3xh54zest5mg6mqh9d; stake1u8t623vc96d5ddstjk46q2l59jeg38y3d0g2asqzf2n2ntqjv72k8; X-avax1h9qxee0820ezfkgeeuc02gkc0c77xrypx8z6g2; bitcoincash:qqkmn6qq7k0wpa5x7qxze5c4lkcsjkrsvsy2ecll6y; bnb1jvds8pg6zkxd2s7dl8klr0dye5avlfv8mm25jm; bc1qkg288agwvjs9cnmhz2q2f4p0x6nttwwngue7v0; 1EZk7eLw52dErMygLvfKQJJ6KVWk8gPgvE; 3K4JfWQv1ye2DAmgfcnMUBJSLnux7Lpf2X; bc1p6nwq0zs0dhcf5zgsfhjrr93enggkzmvqpwxld85egv7zamrcktqsdxmjvt; cosmos13ppe5rlcmlsgp4mlzxuma4nypcgh22upkjgf0k; DNZCS9qtuibaMtgVTf9Ttr7SuXaXRCMsDN; 13ky7J5igHNFeYogpkPh88CzwFNNh46DseTT64uqqvumgeJy | Wuess clipper cryptocurrency address-replacement targets |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
The post Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads appeared first on Cyber Security News.
