clickfixcyberattackcybersecurityHBO MaxSecurity•11:08 AM PDT · September 14, 2026•5 MIN READ
ClickFix attacks are tricking Mac and Windows users into hacking themselves
Aymane Jeddad
Software Engineer
If you clicked on an HBO Max ad on Reddit over the past week, you might want tocheck your computer for malware.
If you clicked on an HBO Max ad on Reddit over the past week, you might want tocheck your computer for malware.These so-called “ClickFix” attacks have quickly become one of the risingcybersecurity threats of 2026, and they’re getting both sneakier andcompromising people’s devices with greater frequency. Until recently, ClickFixattacks were a rarity, capitalizing on people searching the web for quick techfixes. They have since evolved into a massive international effort to hack intopeople’s computers.The attacks involve fake websites, or legitimate websites that have been hacked,which display a message that appears to look like a CAPTCHA or an anti-botcheckbox. Once clicked, a prompt appears asking the user to perform a “check” toproceed, which gives instructions to copy and paste a string of text into theuser’s Windows command prompt or Mac Terminal app. As soon as the user hits return, they unwittingly and instantly installinfo-stealing malware on their computer, capable of immediately stealing theirpasswords, access to their logged-in accounts, and crypto wallets. Since theuser is working in the computer’s terminal, which lets them interact directlywith the operating system using text-based commands, many of these attacks evadeantivirus and security defense tools.Security researchers now say that the latest ClickFix campaign they’ve seeninvolved hackers posting fake ads on Reddit, linking to a page that looks likeHBO Max but contains a ClickFix lure that tricks people into hacking themselves.The hackers compromised the official HBO Max’s account on Reddit that was thenused to post hundreds of fake but real-looking adverts to the news-sharing site,according to security researchers at Hudson Rock[https://www.infostealers.com/article/hbo-max-ads-on-a-compromised-reddit-account-exposed-a-massive-pasteswitch-clickfix-operation/]and a thread[https://www.reddit.com/r/cybersecurity/comments/1w8gu91/reddit_infostealer_adverts/]on Reddit’s cybersecurity subreddit.It’s unclear how many people clicked on these fake ads or how many wereultimately compromised as a result. Warner Brothers Discovery, which owns HBO,did not respond to a request for comment.Reddit told TechCrunch it “recently learned that an HBO Max account authorizedto run advertisements on Reddit was compromised and used to run ads containingmalicious links,” and that the company locked the account and removed the ads.When asked, Reddit did not say how many users were targeted or clicked themalicious ads.While it’s typical for developers to run one-line snippets of code in theircomputer’s terminal, it’s less common for regular users to use the CommandPrompt or PowerShell in Windows, or the Terminal in macOS. Companies that runfleets of Windows computers can block access to these features across the entiredomain to prevent them from being exploited, per security researcher KevinBeaumont [https://cyberplace.social/@GossiTheDog/117248119459924189].As noted by Ars Technica[https://arstechnica.com/security/2026/09/clickfix-attacks-infecting-pcs-and-macs-are-going-viral/],a tool for Mac users called BlockBlock[https://objective-see.org/products/blockblock.html] can also defend againstattacks that try to trick Apple users into hacking themselves.Updated with comment from Reddit.
Overview
If you clicked on an HBO Max ad on Reddit over the past week, you might want tocheck your computer for malware.
KEY TAKEAWAYS
Summary & Principles
- Ingested via N8N automation webhook.
#clickfix#cyberattack#cybersecurity#HBO Max#Security
