Attackers compromised the official HBO Max Reddit account to run fraudulent ads, leveraging its trusted status to deploy a social engineering campaign known as ClickFix. This technique tricks users into executing malicious commands on their macOS or Windows devices, leading to the installation of information-stealing malware. The article does not provide specific software version ranges, CVSS scores, or patch details, focusing instead on the threat actor's method and the incident's impact.
Attackers compromised the verified official HBO Max Reddit account, u/hbomax, and used its trusted advertising status to launch a ClickFix campaign targeting macOS and Windows devices with information-stealing malware. Screenshot of the fraudulent ad (Source: Alex Cutts) ClickFix has been rising in popularity among cybercriminals. It’s a social engineering technique that cons victims into running malicious commands on their own machine, usually by pretending the commands are needed to fix a problem or perform routine … More → The post Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz appeared first on Help Net Security .