HBO Max's Reddit account got hijacked, and whoever took it over used it to try to infect fans with malware.
Someone took over HBO Max's official Reddit account and used the verified handle to push malicious links to the service's Reddit followers. The attack reportedly used ClickFix, a technique that lures people with a fake verification or CAPTCHA screen, then instructs them to paste a command into their computer's run dialog - a command that actually installs malware. Because the message came from a large, trusted brand account, it lent the scam instant credibility. It's not clear yet how the intruders got in, or how long the account was under their control.
ClickFix attacks are spreading precisely because they sidestep the malware defenses built into email and downloads - the trick relies on the victim doing the infecting themselves, one copy-paste at a time. A hijacked account with an established, trusted following is a better delivery vehicle than any phishing email, and this is a reminder that brand trust is now a security liability as much as a marketing asset.
Expect more of this: as platforms crack down on obvious phishing, attackers are increasingly hijacking accounts people already trust instead of building fake ones.