HBO Max Reddit Account Hijacked for ClickFix Malware
TechCrunch reports ClickFix lures ran through a compromised HBO Max Reddit account authorized to buy ads. Hudson Rock and ADAMnetworks say hundreds of fake ads pointed to an HBO Max-looking page that tells users to paste a command into Windows cmd or Mac Terminal.

TechCrunch (Zack Whittaker, 14 September 2026) says ClickFix lures impersonate a CAPTCHA or anti-bot check, then tell the victim to paste a command into Windows Command Prompt or Mac Terminal. The payload is an info-stealer aimed at passwords, logged-in sessions, and crypto wallets. Because the user runs the terminal themselves, many of these installs slip past antivirus.
This is TechCrunch reporting, quoting a Reddit statement on a compromised ad-authorized account. It is not a CVE advisory, and it is not a count of infections.
The latest campaign used the official HBO Max Reddit account that was authorized to run ads. Researchers at Hudson Rock and ADAMnetworks say hundreds of fake but real-looking ads pointed to an HBO Max-looking ClickFix page.
Reddit told TechCrunch it locked that account and removed the ads after learning it had been used to run malicious links. Reddit would not say how many users were targeted or clicked. Warner Bros. Discovery, which owns HBO, did not comment.
Infection and click counts are still unknown. Reddit has confirmed the compromise of an ad-authorized HBO Max account. It has not confirmed every malware family detail in the researcher write-ups.
Related session-theft tape includes the Twitch JeetBot OAuth token leak, exposed Vite servers leaking AWS and Azure keys, and Cyberpresso's secrets-management shortlist.
Treat any unexpected CAPTCHA that asks you to paste text into Terminal or cmd as malware. If you clicked an HBO Max Reddit ad this week, revoke Reddit and browser sessions and scan for info-stealers.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free