Hackers hijack HBO Max’s verified official Reddit account and use it to post and promote malicious advertisements. The campaign directs users to ClickFix pages that attempt to trick visitors into running actions on their own devices, leading to infections.
Across reports, the malvertising focuses on Windows and macOS users and is tied to information-stealing malware. Help Net Security describes the activity as a short, time-bounded blitz lasting about 48 hours, leveraging Reddit trust and the account’s ad status to increase the likelihood that users click. Bleeping Computer and SecurityWeek similarly report that the ads ultimately deliver the ClickFix-style social engineering workflow designed to compromise victims after the user interacts with the prompt.
While the outlets differ mainly in emphasis—some focusing on the hijacked account itself and others on the ClickFix delivery mechanism—the core events are consistent: the compromised Reddit account is used to distribute fraudulent ads, and those ads point to a ClickFix lure targeting macOS and Windows with malware intended to steal information.