HBO Max Reddit Hack: The New ClickFix Malware Threat
The official HBO Max Reddit account was compromised to distribute malware via deceptive ClickFix ads targeting Windows and macOS users.

The risk of trusting verified accounts: the HBO Max hack
Digital security has been put to the test once again following a recent incident on Reddit, where the official HBO Max account was breached by malicious actors. This hack was not a simple act of vandalism, but a sophisticated operation designed to deploy a large-scale malware campaign under the guise of legitimate advertisements.
Attackers leveraged the high visibility of the account to promote links that, under the pretext of fixing technical errors, redirected users to ClickFix schemes. This method tricks victims into executing malicious commands on their machines, compromising both Windows and macOS systems.
What is the ClickFix attack and how does it affect us?
ClickFix is a social engineering technique that exploits user trust. Instead of downloading a file directly, the user is asked to perform a series of steps—such as copying and pasting a command into the terminal or PowerShell—under the premise of repairing a display or connection error.
"Attackers use the trust architecture of social platforms to distribute infostealers capable of silently extracting passwords, session cookies, and financial data."
Although the primary goal in this instance was information theft, these types of entry vectors are common precursors to more destructive ransomware attacks. It is essential to remember that, as was the case with Cybersecurity: New vulnerability in ScreenConnect facilitates attacks, any platform, no matter how large, can have a vulnerability that cybercriminals will not hesitate to exploit.
Essential protective measures
To avoid falling victim to these types of incidents, it is vital to maintain a posture of digital skepticism:
- Be wary of commands: Never copy or paste scripts from unknown sources into your terminal, even if they come from profiles with a blue checkmark.
- Account protection: Organizations must implement robust multi-factor authentication (MFA) to prevent the hijacking of corporate profiles.
- Constant monitoring: Keeping software updated helps mitigate risks, although the human factor remains the final line of defense.
The sophistication of current attacks reminds us that security is not a permanent state, but a constant process of vigilance. The integrity of social media accounts is now a critical asset that must be protected with the same rigor as a company's internal servers.
Related articles
7 de septiembre de 2026
Cybersecurity: New ScreenConnect vulnerability facilitates attacks
Researchers have detected a four-stage infection chain that uses ScreenConnect to compromise systems through malicious scripts.
30 de agosto de 2026
Breach at Manchester Airports Group: The hack exposing 86 GB of data
The group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group, revealing sensitive passenger and booking information.
23 de agosto de 2026
Hackers infect Android car systems: the new vulnerability
A supply chain attack is turning Android-based automotive multimedia systems into part of a botnet, putting driver security at risk.
16 de agosto de 2026
AmnesiaStealer: The new hack compromising macOS security
We analyze AmnesiaStealer, a macOS malware that enables remote browser control and puts user privacy at risk.
Loading comments...