PLATFORMS Signal 39
Hackers hijacked HBO Max’s Reddit advertising account to spread ClickFix malware
Compromised HBO Max Reddit ads have been used to lure Mac and Windows users into running malicious terminal commands that install credential-stealing malware.
The attack bypasses traditional antivirus by executing directly in the OS shell, giving threat actors immediate access to passwords, logged-in sessions, and crypto wallets. Enterprises that allow terminal use across fleets must consider policy controls, and individual users need to treat any unsolicited command-line prompt as suspicious.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Fake HBO Max ads on Reddit link to pages that mimic CAPTCHAs and request a copy-paste command into the terminal.
Executing the command installs info-stealing malware that can harvest credentials and crypto assets.
Reddit confirmed the HBO Max ad account was compromised, locked it, and removed the malicious ads.
THE CLUSTER
↗