Attackers seized control of the verified Reddit account belonging to HBO Max and turned it into a distribution channel for information-stealing malware aimed at Windows and macOS users, according to a Bitdefender report published today. The intruders ran more than 100 malicious advertisements through the account over roughly two days, the report says. Bitdefender has not said when the account was compromised, and neither HBO Max nor Reddit has issued a statement in the document.
Some of the ads posed as a macOS application from HBO Max, a product that does not actually exist; others pushed bogus AI and developer tools along with Mac utilities, the report says. That mismatch is the tell: anyone who clicked expecting a download was instead routed into a scheme designed to make them infect their own machine. Researchers have tied the activity to a wider cross-platform effort known as PasteSwitch.
The technique at the center of the campaign is known as ClickFix, which relies on convincing a victim to carry out the infection personally. Lures present themselves as a CAPTCHA challenge, an error notice, or a setup guide, and the instructions that follow tell the user to paste a command into a system tool. On Windows that means PowerShell or another built-in utility; on Macs it means Terminal. Once pasted, the command may pull down and run further malicious code. Because the attack leans on tools already present in the operating system, it slips past some of the warnings that would normally flag a download.
Citing reporting from The Register and BleepingComputer, Bitdefender says the macOS payloads seen in the campaign include MacSync and malware tied to AMOS. MacSync can target browser-stored credentials, Firefox profiles, Telegram, Apple Notes, and macOS passwords. The same campaign also pushed counterfeit cryptocurrency wallets built to capture recovery phrases.
Apple has added defenses that bear directly on this style of attack. From macOS Tahoe 26.4 onward, the report says, Macs can show a warning to people who rarely use Terminal when text copied out of a browser, email client, or messaging app is pasted there, and XProtect can inspect what those pasted commands set off and block ones already known to be malicious. The report points to "Possible malware, Paste blocked" as one such message from macOS. Apple's guidance is not to proceed unless the user is certain where the command came from. Bitdefender notes the warning can still be dismissed in some situations, and that attackers keep rewriting their instructions.
For anyone who already pasted a command, Bitdefender recommends running a full security scan, using Bitdefender Total Security for the job. Passwords for important accounts should be changed from a clean device, unfamiliar sessions revoked, and multi-factor authentication or passkeys switched on. A stolen crypto seed phrase is a different problem: unlike a password, it cannot be reset.
Bitdefender's broader advice is to treat no command from a website as safe to paste into Terminal, PowerShell, Command Prompt, or the Windows Run box. A verified badge on a social account is not proof that what it advertises is legitimate, the report warns. Software should come from official sources or trusted app stores, operating systems and security tools kept current, and security warnings never overridden on a website's say-so.
The campaign lands days after Bitdefender detailed a separate breach in which a legacy login integration between Dropbox and Lenovo allowed access to about 5,000 Dropbox accounts between 4 and 21 August. In that case Dropbox notified those affected and described the cause as "an issue with Lenovo's email verification process".













