Ad fraud is trending, and this is what it looks like: a hijacked HBO Max account pushing malware
The other advertising story spiking this week is not a campaign, it is the pipeline being weaponized. Hackers took over HBO Max’s Reddit account and ran more than a hundred ads that walked users into installing malware on themselves. It is a useful reminder that the ad you trust is only as safe as the account serving it.
When “ad fraud” trends, it is easy to picture spreadsheets and fake clicks. This week it looks like something nastier. Attackers hijacked HBO Max’s verified Reddit account and used it to run a wave of malicious ads that tricked Mac and Windows users into infecting their own machines.
What happened
Over roughly 48 hours the compromised account served more than a hundred ads that pointed to a spoofed HBO Max page. There, users met a fake CAPTCHA or anti bot prompt and were told to copy a line of text and paste it into their Windows Command Prompt or macOS Terminal. Running it installed information stealing malware. Security researchers pieced the campaign together after a Reddit user flagged the ads, Help Net Security reported.
At a glance
- The trend
- “Ad fraud” spiking on the back of a malvertising campaign, not fake-click reports
- The vector
- HBO Max’s hijacked Reddit account served 100+ malicious ads over about 48 hours
- The trap
- A spoofed page + fake CAPTCHA told users to paste a command that installed infostealer malware
- The technique
- ClickFix: social engineering that makes the victim run the malicious command themselves
What ClickFix is
The technique is called ClickFix, and it is spreading fast because it turns the victim into the attacker’s hands. Instead of exploiting a software hole, it uses a social engineering script: pose as a routine fix or a human check, then get the person to run the command themselves. A real CAPTCHA never asks you to open a terminal.
Why it belongs on an ad watch site
Our beat is what advertising does, and this is its underbelly. The same machinery that puts a sneaker or a betting app in front of you, trusted brand accounts and the programmatic ad pipeline, can be rented or stolen to deliver malware. It is not a one off either: researchers have tracked malvertising that abused Google Ads and even a chatbot’s share feature to host the same ClickFix lures.
How not to get hit
The defense is simple and worth repeating: never paste a command you did not write into a terminal, no matter what page told you to. No legitimate verification step, and no real streaming service, will ever ask you to.
Sources & further reading
- TechCrunch: ClickFix attacks are tricking Mac and Windows users into hacking themselves
- The Register: HBO Max Reddit account compromised to serve ClickFix attacks
- Help Net Security: Attackers hijack HBO Max’s Reddit account for a 48-hour malvertising blitz
- Trend Micro: Threat actors abuse claude.ai shared chat for a ClickFix malvertising campaign




