A series of suspicious advertisements flooded the social news platform Reddit over a 48-hour period, according to a recent report. These ads, totaling 108, were posted from u/hbomax, the official and verified account of HBO Max, a popular streaming service. The alert was raised by a user who noticed something unusual about one of the ads. Researchers from ADAMnetworks and HudsonRock, two cybersecurity firms, jointly investigated the issue and shared their findings on September 13, 2026. Their analysis revealed that the ads were promoting a non-existent native HBO Max application for macOS and directed users to a counterfeit website designed to look exactly like the official HBO Max site.
The attack did not rely on hacking into systems directly but instead used psychological tactics to trick users. When users clicked on the download button on the fake site, they were presented with a "ClickFix" prompt. This window asked them to copy a command and paste it into their computer's terminal (on Mac) or an equivalent program on Windows, then execute it. This method allowed users to unknowingly install malicious software, bypassing many of the security measures designed to block suspicious downloads. The ultimate goal of the attack was to trick users into downloading an infostealer—a type of malware that can steal login credentials, browser data, messages, and cryptocurrency wallet information. On Windows, some of the malicious activity was even disguised as normal Facebook traffic to avoid detection.
Following the discovery, Reddit took action and suspended the ads linked to the compromised account. Warner Bros., the parent company of HBO Max, was informed about the incident, but as of now, there has been no official response. Neither Reddit nor the researchers have disclosed how many users actually clicked on the ads and executed the deceptive command. The full scope of the breach remains unclear, raising concerns about the security of online platforms and the potential for similar attacks in the future.
This incident highlights the growing threat of social engineering attacks, where users are manipulated into compromising their own security. Unlike traditional hacking methods, these attacks exploit human behavior rather than technical vulnerabilities. As online platforms continue to evolve, it becomes increasingly important for users to remain vigilant and cautious when interacting with unfamiliar links or prompts, especially those that ask for direct system access.
Malicious Ads Target HBO Max Users on Reddit
AI-rewritten from original reportingHow it works
malwaresocialengineeringphishingreddithbo-maxadsecurity



