Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
BLUF
Compromised social media accounts are being weaponized to deliver infostealers via social engineering campaigns.
NEWS
Threat actors seized control of the official HBO Max Reddit profile on September 14, 2026, to post malicious ads utilizing ClickFix techniques. These posts tricked visitors into executing commands that installed information-stealing malware on their systems. The attack successfully leveraged brand trust to bypass user skepticism regarding security warnings.
Why I Care
This breach demonstrates how account takeovers on trusted platforms can rapidly scale malware distribution, putting millions of users at risk of credential theft. Affected individuals face immediate financial and privacy risks, while brands suffer reputational damage and loss of community trust.
Next Steps
End users who visited the subreddit should run full antivirus scans and rotate all credentials immediately. Security administrators must update blocklists with associated ClickFix IOCs and monitor for similar social media impersonation attempts today. Brand owners should audit access controls on all external communication channels to enforce stricter authentication protocols.
Source: BleepingComputer ·