Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Refract AI Intelligence Digest

BLUF

Compromised social media accounts are being weaponized to deliver infostealers via social engineering campaigns.

NEWS

Threat actors seized control of the official HBO Max Reddit profile on September 14, 2026, to post malicious ads utilizing ClickFix techniques. These posts tricked visitors into executing commands that installed information-stealing malware on their systems. The attack successfully leveraged brand trust to bypass user skepticism regarding security warnings.

Why I Care

This breach demonstrates how account takeovers on trusted platforms can rapidly scale malware distribution, putting millions of users at risk of credential theft. Affected individuals face immediate financial and privacy risks, while brands suffer reputational damage and loss of community trust.

Next Steps

End users who visited the subreddit should run full antivirus scans and rotate all credentials immediately. Security administrators must update blocklists with associated ClickFix IOCs and monitor for similar social media impersonation attempts today. Brand owners should audit access controls on all external communication channels to enforce stricter authentication protocols.

Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.