ClickFix attacks are tricking Mac and Windows users into hacking themselves
image via TechCrunch
September 14, 2026, 6:08 PM
- •Security researchers said attackers used a compromised HBO Max advertising account on Reddit to post malicious ads linking to a fake HBO Max page.
- •The fake page displayed a CAPTCHA-like prompt that instructed users to copy and paste text into Windows Command Prompt, PowerShell, or macOS Terminal.
- •Running the pasted command could install info-stealing malware capable of taking passwords, session access, and cryptocurrency wallets.
- •Reddit said it locked the compromised advertising account and removed the malicious ads after learning of the incident.
- •Researchers cited in the article included Hudson Rock, ADAMnetworks, and Kevin Beaumont; Ars Technica was also referenced for Mac-focused defenses such as BlockBlock.
Researchers say attackers used a compromised HBO Max advertising account on Reddit to spread ClickFix malware lures. The ads linked to a fake HBO Max page that showed a CAPTCHA-like prompt and told users to paste commands into Windows or macOS terminal tools. Executing those commands could instantly install info-stealing malware designed to grab passwords, active account access, and crypto wallets. Reddit said it locked the account and removed the ads, while researchers warned that this social-engineering technique is becoming a major cyber threat.
Entities Mentioned
Zack WhittakerKevin Beaumont
Topics Covered
SecurityclickfixcyberattackcybersecurityHBO MaxCybersecurityMalwareSocial EngineeringRedditWindowsMacOS
Comments (0)
No comments yet.