· via TechCrunch
ClickFix attacks spread through hijacked HBO Max Reddit ads on Mac and Windows
Attackers compromised an HBO Max advertising account on Reddit to push ClickFix lures — fake CAPTCHAs that convince Mac and Windows users to paste malware commands into their own terminals.

Reddit users who interacted with HBO Max advertisements over the past week should consider checking their computers for malware, according to TechCrunch. Attackers hijacked an HBO Max advertising account on the platform and used it to run hundreds of convincing but malicious ads, in what security researchers describe as the latest escalation of ClickFix, one of the fastest-growing cyber threats of 2026.
How the trick works
ClickFix is a social-engineering scheme that gets victims to compromise their own machines. It begins on a counterfeit website, or a legitimate site that attackers have breached, where visitors see something that resembles a CAPTCHA or an anti-bot checkbox. After clicking, a prompt appears telling them to complete a "check" before they can continue — instructions that amount to copying a line of text and pasting it into the Windows Command Prompt or PowerShell, or the macOS Terminal.
When the user presses return, TechCrunch reports, the pasted text installs info-stealing malware on the spot. The payload can harvest passwords, hijack logged-in sessions and drain cryptocurrency wallets. Because the malicious code runs through the machine's own command-line interface at the user's hands, many of these attacks evade antivirus and other security defenses entirely.
Developers routinely run one-line commands in a terminal, but ordinary users almost never open these tools voluntarily — and a website instructing them to do so is precisely the tell that makes the attack work on the unwary.
A hijacked brand account
According to researchers at Hudson Rock and a thread on Reddit's cybersecurity community, the newest campaign used the official HBO Max Reddit account, one specifically authorized to buy advertising, to seed the platform with fake but realistic adverts. The ads linked to a page styled to look like the HBO Max streaming service, complete with a ClickFix lure.
TechCrunch says it is unclear how many people clicked the ads or were ultimately infected. Warner Bros. Discovery, which owns HBO, did not respond to a request for comment.
A Reddit spokesperson told TechCrunch that the company had discovered the compromised ad account was used to serve promotions containing malicious links, and that it has since locked the account and removed the advertisements. Reddit did not disclose how many users were shown or clicked the malicious ads.
What can block it
For organizations, security researcher Kevin Beaumont notes that companies managing fleets of Windows machines can disable access to command-line tools across an entire domain, closing off the pathway ClickFix depends on. On the Mac side, Ars Technica points to BlockBlock, a utility built to detect and stop attacks that coax Apple users into running malicious commands themselves.
For individuals, the defense is simpler: no genuine CAPTCHA or bot check will ever ask you to paste a command into a terminal. Any website that does is trying to install malware.
Why it matters
ClickFix has evolved from a niche trick aimed at people hunting for quick tech fixes into what TechCrunch describes as a large, coordinated international hacking effort. Its power comes from inverting the usual attack model: rather than exploiting a software vulnerability, it exploits the person, executing malicious code with the user's own privileges through a tool that security software tends to trust.
The Reddit campaign adds a second troubling dimension. By compromising an account authorized to buy ads under a major brand's name, the attackers borrowed HBO Max's credibility and Reddit's own advertising infrastructure, making the lure far harder to spot than a random pop-up on a shady site. And because the technique requires no exploit at all — just persuasion — both Windows and macOS users remain exposed, and ad-platform account security is now part of the malware supply chain.
- #clickfix
- #malware
- #social-engineering
- #cybersecurity