- A verified advertising identity did not authenticate the destination.
What changed
ADAMnetworks published joint research with Hudson Rock linking a compromised official HBO Max Reddit account to PasteSwitch. The researchers counted 108 malicious advertisements over 48 hours. Fake software pages instructed visitors to paste commands into Terminal, and the investigation connected the delivery operation to macOS stealers and Windows malware.
Why it matters
The significant mechanism is the transfer of trust: a familiar account attracts a click, but an unrelated website supplies instructions that execute outside the browser. The findings give defenders a concrete reason to examine the full path from advertisement to installer.
What remains unproven
The report does not establish how the account was first compromised or the total number of infected users. The HBO-themed domains had stopped delivering payloads when ADAMnetworks examined the campaign.
Read beyond this page.
Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.
Changes & version history
Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review
Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release
Version 1 · 15 Sep 2026
Source-linked private review edition
