ClickFix Attacks Trick Mac and Windows Users Into Installing Malware on Their Own Computers

A cybersecurity threat known as “ClickFix” is compromising Mac and Windows computers at an increasing rate in 2026, with hackers most recently exploiting a hijacked HBO Max Reddit account to spread malware through fake advertisements.

ClickFix attacks work by directing users to fake or compromised websites that display what appears to be a CAPTCHA or anti-bot verification prompt. Once clicked, the page instructs users to copy and paste a string of text into their Windows Command Prompt or Mac Terminal app. When the user presses return, info-stealing malware installs instantly — capable of harvesting passwords, account access, and crypto wallet data. Because the commands run directly through the operating system’s terminal, many of these attacks bypass antivirus and other security tools.

The most recent campaign, identified by security researchers at Hudson Rock and flagged in Reddit’s cybersecurity community, involved hackers compromising HBO Max’s official Reddit advertising account. The account was then used to post hundreds of fake but convincing ads linking to a page designed to look like HBO Max, which contained the ClickFix lure. Reddit confirmed to TechCrunch that it “recently learned that an HBO Max account authorized to run advertisements on Reddit was compromised and used to run ads containing malicious links,” adding that it locked the account and removed the ads. Reddit did not disclose how many users were targeted or clicked the malicious links. Warner Bros. Discovery, which owns HBO, did not respond to a request for comment.

It is unclear how many users were ultimately compromised. ClickFix attacks were previously rare, targeting people searching for quick tech fixes online, but have since expanded into a large-scale international hacking effort.

Security researcher Kevin Beaumont noted that companies managing fleets of Windows computers can block access to Command Prompt and PowerShell across their domain to reduce exposure. For Mac users, a tool called BlockBlock can help defend against attacks that attempt to exploit the Terminal, according to Ars Technica.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top