PasteSwitch ClickFix malware delivery of MacSync, AMOS helper, and Amatera Stealer
Malware Activity
Summary
Hide ▲
Show ▼
The PasteSwitch activity is using ClickFix ads to deliver MacSync, AMOS helper, and Amatera Stealer to Windows and macOS users, creating a high-risk path to credential theft and account compromise. A hijacked HBO Max Reddit account amplified the reach with 108 malicious ads over about 48 hours. The delivery chain relies on attacker-supplied commands pasted into trusted operating-system tools, helping the malware bypass some browser and security defenses.
Related Happenings
PasteSwitch malicious ClickFix ads campaign via HBO Max Reddit account
Campaign
H score32
First: 21.09.2026 11:39
Last: 21.09.2026 11:39
Sources 1
About this happening:
The PasteSwitch campaign abused HBO Max's official Reddit account (u/hbomax) to push 108 malicious ads over 48 hours, turning a trusted brand channel into a delive...
PasteSwitch malicious ClickFix ads campaign via HBO Max Reddit account
CampaignAbout this happening: The PasteSwitch campaign abused HBO Max's official Reddit account (u/hbomax) to push 108 malicious ads over 48 hours, turning a trusted brand channel into a delive...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityAbout this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
Go-based macOS stealer with DRAIN wallet-draining routine
Malware Activity
H score29
First: 07.08.2026 21:29
Last: 07.08.2026 21:29
Sources 1
About this happening:
A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...
Go-based macOS stealer with DRAIN wallet-draining routine
Malware ActivityAbout this happening: A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...
ClickFix macOS Terminal-command lure campaign
Campaign
H score42
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix macOS Terminal-command lure campaign
CampaignAbout this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix Go-based macOS infostealer and crypto drainer
Malware Activity
H score29
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
ClickFix Go-based macOS infostealer and crypto drainer
Malware ActivityAbout this happening: A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
Timeline
-
14.09.2026 21:34 2 articles · 7d ago
HBO Max Reddit account hijack drives ClickFix malware ads
Initial DisclosureResearchers said the verified u/hbomax Reddit account for HBO Max was hijacked and used to run 108 malicious advertisements over about 48 hours, steering users to fake HBO Max download pages and ClickFix prompts that told them to paste commands into Windows Run, PowerShell, or macOS Terminal. The broader PasteSwitch campaign delivered MacSync, AMOS helper, and Amatera Stealer, and also pushed fake Ledger, Trezor Suite, and Exodus wallet apps plus AnimateClipper and ZigClipper.
Show sources
- Hackers hijack HBO Max Reddit account to push malware in ClickFix ads — www.bleepingcomputer.com — 14.09.2026 21:34
- Hackers hijack HBO Max Reddit account to push malware in ClickFix ads — www.bleepingcomputer.com — 14.09.2026 21:34