Hijacked HBO Max Reddit account pushed 108 ClickFix ads in 48 hours
TechNadu · x · 2026-09-15
Security outlet TechNadu reports on the "PasteSwitch" campaign: HBO Max's verified Reddit account was hijacked to push 108 ClickFix-style ads in 48 hours, luring users to a fake HBO Max app.
- The fake app branched into different malware chains depending on whether the victim ran macOS or Windows.
- Some crypto-clipping malware pulled instructions from Binance Smart Chain contracts to complicate takedown and attribution.
- The operation relies on ClickFix social engineering, tricking users into running malicious commands as if performing normal fixes.
More from Safety
- Critic warns against conflating vibes-based AI risk estimates with empirical likelihoods — merrierm · 2026-09-15
- New arXiv paper invites mathematicians to tackle AI safety, field by field — stevenstrogatz · 2026-09-15
- p(doom) is vibes, not statistics: researcher offers a VET framework for AI discourse — merrierm · 2026-09-15
- FT: UKAISI denied pre-release access to Mythos 5.1, UK MPs warn of security risk — Chris_Brannigan · 2026-09-15
- AI safety argued via nuclear precedent: powerful tech needs rules, but liability stays with companies — shlomifruchter · 2026-09-15
- EA insiders debate whether AI Safety community health will repeat CEA's HR-style mistakes — JMannhart · 2026-09-15