PasteSwitch malicious ClickFix ads campaign via HBO Max Reddit account
Campaign
Summary
Hide ▲
Show ▼
The PasteSwitch campaign abused HBO Max's official Reddit account (u/hbomax) to push 108 malicious ads over 48 hours, turning a trusted brand channel into a delivery route for ClickFix attacks. The operation infected Windows and macOS users with information-stealing malware in mid-September 2026. The lure relied on a verified account to lower suspicion and widen exposure. The campaign spread theft-oriented payloads across both desktop ecosystems.
Related Happenings
ChainScript RAT delivered via ClickFix-like lures
Malware Activity
H score23
First: 21.09.2026 11:39
Last: 21.09.2026 11:39
Sources 1
How related:
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript.
About this happening:
The ChainScript RAT is being delivered through ClickFix-like lures, giving operators remote access and payload deployment control on compromised Windows system...
ChainScript RAT delivered via ClickFix-like lures
Malware ActivityHow related: Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript.
About this happening: The ChainScript RAT is being delivered through ClickFix-like lures, giving operators remote access and payload deployment control on compromised Windows system...
PasteSwitch ClickFix malware delivery of MacSync, AMOS helper, and Amatera Stealer
Malware Activity
H score29
First: 14.09.2026 21:34
Last: 14.09.2026 21:34
Sources 1
About this happening:
The PasteSwitch activity is using ClickFix ads to deliver MacSync, AMOS helper, and Amatera Stealer to Windows and macOS users, creating a high-risk pa...
PasteSwitch ClickFix malware delivery of MacSync, AMOS helper, and Amatera Stealer
Malware ActivityAbout this happening: The PasteSwitch activity is using ClickFix ads to deliver MacSync, AMOS helper, and Amatera Stealer to Windows and macOS users, creating a high-risk pa...
REVSTEALER game-cheat lure campaign on hijacked YouTube channels
Campaign
H score25
First: 06.09.2026 11:34
Last: 06.09.2026 11:34
Sources 1
About this happening:
The REVSTEALER distribution campaign is still reaching new victims through game-cheat lures, widening exposure across at least 17 hijacked YouTube channels and two che...
REVSTEALER game-cheat lure campaign on hijacked YouTube channels
CampaignAbout this happening: The REVSTEALER distribution campaign is still reaching new victims through game-cheat lures, widening exposure across at least 17 hijacked YouTube channels and two che...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
Campaign
H score38
First: 24.07.2026 18:12
Last: 24.07.2026 18:12
Sources 1
About this happening:
BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
CampaignAbout this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
ClickFix mitigation guidance for Windows and macOS
Defensive Guidance
H score34
First: 30.06.2026 15:00
Last: 30.06.2026 15:00
Sources 1
About this happening:
Organizations are being urged to harden defenses against ClickFix on Windows and macOS, reducing the chance that social-engineering lures can turn trusted dialogs into...
ClickFix mitigation guidance for Windows and macOS
Defensive GuidanceAbout this happening: Organizations are being urged to harden defenses against ClickFix on Windows and macOS, reducing the chance that social-engineering lures can turn trusted dialogs into...
Timeline
-
21.09.2026 11:39 2 articles · 12h ago
PasteSwitch malicious ClickFix ads campaign via HBO Max Reddit account
Initial DisclosureA compromised HBO Max Reddit account (u/hbomax) was first repurposed to publish malicious ads. The opening wave used ClickFix lures to push theft malware toward Windows and macOS users.
Show sources
- ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure — thehackernews.com — 21.09.2026 11:39
- ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure — thehackernews.com — 21.09.2026 11:39