Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

HBO Max Reddit Account Compromised in Malvertising Blitz Targeting macOS and Windows Machines with Malware




A recent incident involving the HBO Max Reddit account has shed light on the increasingly sophisticated and widespread nature of cybercrimes. A Reddit user discovered that the official HBO Max account had been compromised and used to serve more than 100 malicious ads, specifically designed to target macOS and Windows machines with information-stealing malware known as infostealers. This article provides a detailed analysis of the incident, highlighting the tactics used by attackers and the importance of robust security measures in preventing the spread of malware.



  • Malicious ads served on HBO Max Reddit account infected over 100 macOS and Windows machines with information-stealing malware.
  • The attacks were part of a coordinated effort using fake OpenAI Codex ads, developer-tool lures, and compromised HBO Max Reddit account.
  • Attackers used 108 distinct ads, many of which targeted macOS and Windows machines, including cryptocurrency clippers and hardware devices.
  • The incident highlights the vulnerability of social media platforms to cyber threats and the need for robust security measures.
  • Malvertising is a growing concern, with attackers seeking to capitalize on the trust and security of reputable websites and social media platforms.
  • Security experts emphasize the need for stronger enforcement of right-to-repair rules and trusted distribution channels to prevent malware spread.



  • A recent incident involving the HBO Max Reddit account has shed light on the increasingly sophisticated and widespread nature of cybercrimes. A Reddit user discovered that the official HBO Max account had been compromised and used to serve more than 100 malicious ads, specifically designed to target macOS and Windows machines with information-stealing malware known as infostealers. The malicious ads, part of a 48-hour malvertising blitz, were found to be accompanied by an array of other malware-laden payloads, including cryptocurrency clippers, fake cryptocurrency wallet applications, and even a hardware device capable of RAMming into encrypted memory, exposing user data.

    The attacks were found to be the result of a coordinated effort by attackers, who utilized a range of tactics, including the use of a compromised HBO Max Reddit account, fake OpenAI Codex ads, and developer-tool lures. Researchers at Hudson Rock and ADAMnetworks analyzed the ads, revealing that they served 108 distinct ads, many of which targeted macOS and Windows machines. The attackers utilized a variety of software lures, including disk-cleaner and AI-themed lures, in an effort to trick users into downloading malware onto their machines.

    The incident serves as a stark reminder of the ever-evolving nature of cyber threats. The use of malvertising, in particular, has become a growing concern, as attackers seek to capitalize on the trust and security of reputable websites and social media platforms. In this case, the compromise of the HBO Max Reddit account was found to be part of a larger malvertising blitz, which targeted macOS and Windows machines with a range of malware-laden payloads.

    The attackers' use of a compromised HBO Max Reddit account highlights the vulnerability of social media platforms to cyber threats. The fact that the attackers were able to gain access to the account and utilize it to serve malicious ads is a stark reminder of the importance of robust security measures and the need for users to remain vigilant when interacting with online content.

    In addition to the HBO Max incident, researchers have observed a range of other suspicious activity, including the use of developer-tool lures and fake OpenAI Codex ads. The attackers' use of blockchain-based command-and-control fallbacks for their cryptocurrency clippers further underscores the sophistication and complexity of the attacks.

    The incident has sparked concerns among security experts, who have highlighted the need for stronger enforcement of right-to-repair rules and the importance of trusted distribution channels in preventing the spread of malware. The use of malvertising as a tool for spreading malware-laden payloads has become increasingly prevalent, and the incident serves as a stark reminder of the need for users to remain vigilant and take steps to protect themselves from cyber threats.

    In conclusion, the compromise of the HBO Max Reddit account and the subsequent malvertising blitz have highlighted the growing concern of cyber threats and the need for robust security measures. As attackers continue to evolve and adapt their tactics, it is essential that users remain vigilant and take steps to protect themselves from malware-laden payloads.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/HBO-Max-Reddit-Account-Compromised-in-Malvertising-Blitz-Targeting-macOS-and-Windows-Machines-with-Malware-ehn.shtml

  • https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408

  • https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/


  • Published: Mon Sep 14 18:37:49 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us