3 hrs ago
Hackers Used Fake HBO Max Ads In ClickFix Attack
Hackers reportedly took control of HBO Max’s verified Reddit account.
They used it to post fake ads.
The ads appeared over about two days.
Clicking them could start a type of attack called ClickFix.
The attack targeted both Windows and macOS computers.
Its goal was to install malware that steals information.
Security researchers from Hudson Rock and ADAMnetworks studied the campaign.
The incident shows that even trusted online accounts can be misused by attackers.
Hackers reportedly took over HBO Max’s verified Reddit account.
The account was used to publish 108 malicious ads over about 48 hours.
The ads launched ClickFix attacks targeting Windows and macOS devices.
The attacks were designed to install information-stealing malware.
Security researchers at Hudson Rock and ADAMnetworks analyzed the campaign.
- Who
- Hackers, reportedly using HBO Max’s verified Reddit account, targeted Windows and macOS users; researchers at Hudson Rock and ADAMnetworks analyzed the campaign.
- What
- A campaign used fake HBO Max ads to launch ClickFix attacks and install information-stealing malware.
- Where
- The activity took place through HBO Max’s verified Reddit account and targeted Windows and macOS devices.
- When
- The malicious ads were reportedly published over about 48 hours.
- Why
- The attacks were intended to infect devices with information-stealing malware.
Key facts
- Compromised account
- HBO Max’s verified Reddit account, identified as u/hbomax
- Malicious ads
- 108 ads were reportedly triggered
- Campaign duration
- About 48 hours
- Attack method
- ClickFix
- Target platforms
- Windows and macOS devices
- Malware purpose
- Stealing information
- Researchers
- Hudson Rock and ADAMnetworks






