ClickFix attacks are tricking Mac and Windows users into hacking themselves
Security researchers say a wave of 'ClickFix' attacks delivered through fake HBO Max adverts on Reddit have been luring users into pasting commands into their Mac Terminal or Windows Command Prompt, which then install info-stealing malware. Reddit says an authorized HBO Max account was compromised and used to run the malicious ads, which it has since removed.

Why It Matters
Because these attacks coax nontechnical users to execute command-line instructions, they can bypass conventional antivirus defenses and immediately harvest passwords, account sessions and crypto wallets — increasing the scope and stealth of the campaign.
Key Facts
- Threat name: ClickFix
- Vector: Fake ads on Reddit linking to malicious pages that prompt users to paste commands into Terminal/Command Prompt
- Targeted platforms: macOS and Windows
- Malware capability: Info-stealing: passwords, logged-in accounts, crypto wallets
- Compromised account: An HBO Max account authorized to run ads on Reddit
Researchers monitoring a recent ClickFix campaign report that attackers posted counterfeit HBO Max advertisements on Reddit that directed visitors to pages designed to look legitimate. Those landing pages presented what resembled a CAPTCHA or an anti-bot prompt and then instructed users to copy and paste a line of text into their system shell.
When a user follows the instruction and runs the pasted command in the Windows Command Prompt, PowerShell or macOS Terminal, the action executes code that installs information-stealing malware. Security analysts say the resulting payloads can immediately capture stored credentials, hijack active sessions and access cryptocurrency wallets, while running from the terminal helps the malware evade some endpoint defenses.
Researchers from Hudson Rock and contributors to a Reddit cybersecurity thread say the attackers gained control of an HBO Max account authorized to run ads and used it to distribute hundreds of realistic-looking adverts. Reddit told TechCrunch it locked the compromised account and removed the malicious ads, but the company did not disclose how many users saw or clicked the links. Warner Bros. Discovery did not reply to a request for comment.
Experts point to practical mitigations for organizations and users: blocking access to command-line tools across managed Windows domains can reduce risk, according to researcher Kevin Beaumont, and macOS users can consider defenses such as the BlockBlock tool noted by Ars Technica. Because many everyday users do not normally run one-line shell snippets, the campaigns rely on social engineering — and anyone who clicked these ads in the past week is advised to check their devices for signs of compromise.
Keep Reading

macOS 27: new Siri takes on AI productivity apps

With iOS 27, I’m actually using Siri again

Amazon Prime Video takes on TikTok with short-form news clips
