ClickFix assaults are tricking Mac and Home windows customers into hacking themselves


If you happen to clicked on an HBO Max advert on Reddit over the previous week, you would possibly need to verify your laptop for malware.

These so-called “ClickFix” assaults have shortly turn into one of many rising cybersecurity threats of 2026, they usually’re getting each sneakier and compromising folks’s gadgets with higher frequency. Till just lately, ClickFix assaults had been a rarity, capitalizing on folks looking the online for fast tech fixes. They’ve since developed into a large worldwide effort to hack into folks’s computer systems.

The assaults contain pretend web sites, or reputable web sites which were hacked, which show a message that seems to seem like a CAPTCHA or an anti-bot checkbox. As soon as clicked, a immediate seems asking the consumer to carry out a “verify” to proceed, which provides directions to repeat and paste a string of textual content into the consumer’s Home windows command immediate or Mac Terminal app. 

As quickly because the consumer hits return, they unwittingly and immediately set up info-stealing malware on their laptop, able to instantly stealing their passwords, entry to their logged-in accounts, and crypto wallets. Because the consumer is working within the laptop’s terminal, which lets them work together instantly with the working system utilizing text-based instructions, many of those assaults evade antivirus and safety protection instruments.

Safety researchers now say that the newest ClickFix marketing campaign they’ve seen concerned hackers posting pretend adverts on Reddit, linking to a web page that appears like HBO Max, however incorporates a ClickFix lure that methods folks into hacking themselves. The hackers compromised the official HBO Max’s account on Reddit that was then used to submit a whole bunch of faux however real-looking adverts to the news-sharing web site, in keeping with safety researchers at Hudson Rock and a thread on Reddit’s cybersecurity subreddit.

It’s unclear how many individuals clicked on these pretend adverts or what number of had been in the end compromised because of this. Warner Brothers Discovery, which owns HBO, didn’t reply to a request for remark; neither did Reddit.

Whereas it’s typical for builders to run one-line snippets of code of their laptop’s terminal, it’s much less widespread for normal customers to make use of the Command Immediate or PowerShell in Home windows, or the Terminal in macOS. Corporations that run fleets of Home windows computer systems can block entry to those options throughout the complete area to forestall them from being exploited, per safety researcher Kevin Beaumont.

As famous by Ars Technica, a device for Mac customers referred to as BlockBlock can even defend towards assaults that attempt to trick Apple customers into hacking themselves.

Once you buy by way of hyperlinks in our articles, we might earn a small fee. This doesn’t have an effect on our editorial independence.