ClickFix Attacks Are Tricking Mac and Windows Users Into Hacking Themselves
If you clicked on an HBO Max ad on Reddit over the past week, you might want to check your computer for malware. ClickFix attacks have quickly become one of the rising cybersecurity threats of 2026, and they are getting both sneakier and more frequent. Until recently, these attacks were a rarity, capitalizing on people searching the web for quick tech fixes. They have since evolved into a massive international effort to hack into people’s computers.
- ClickFix Attacks Are Tricking Mac and Windows Users Into Hacking Themselves
- How the Latest ClickFix Attacks Spread Through Reddit
- Why ClickFix Attacks Evade Security Tools
- Who Is Most at Risk From ClickFix Attacks
- How to Protect Yourself From ClickFix Attacks
- The Bigger Picture Behind ClickFix Attacks
- Final Thoughts on ClickFix Attacks
The attacks involve fake websites, or legitimate websites that have been hacked, which display a message that appears to look like a CAPTCHA or an anti-bot checkbox. Once clicked, a prompt appears asking the user to perform a “check” to proceed. That prompt gives instructions to copy and paste a string of text into the user’s Windows command prompt or Mac Terminal app.
As soon as the user hits return, they unwittingly and instantly install info-stealing malware on their computer. This malware is capable of immediately stealing passwords, access to logged-in accounts, and crypto wallets. Since the user is working in the computer’s terminal, which lets them interact directly with the operating system using text-based commands, many of these attacks evade antivirus and security defense tools.
How the Latest ClickFix Attacks Spread Through Reddit
Security researchers now say that the latest ClickFix campaign they have seen involved hackers posting fake ads on Reddit. These ads linked to a page that looked like HBO Max but contained a ClickFix lure that tricks people into hacking themselves. The hackers compromised the official HBO Max account on Reddit, which was then used to post hundreds of fake but real-looking adverts to the news-sharing site, according to security researchers at Hudson Rock and a thread on Reddit’s cybersecurity subreddit.
It is unclear how many people clicked on these fake ads or how many were ultimately compromised as a result. Warner Brothers Discovery, which owns HBO, did not respond to a request for comment.
Reddit told TechCrunch it “recently learned that an HBO Max account authorized to run advertisements on Reddit was compromised and used to run ads containing malicious links.” The company said it locked the account and removed the ads. When asked, Reddit did not say how many users were targeted or clicked the malicious ads.
Why ClickFix Attacks Evade Security Tools
While it is typical for developers to run one-line snippets of code in their computer’s terminal, it is less common for regular users to use the Command Prompt or PowerShell in Windows, or the Terminal in macOS. This gap in familiarity is exactly what ClickFix attacks exploit.
Because the user is manually pasting and running the code themselves, the attack often bypasses traditional antivirus and security defense tools. The terminal gives the code direct access to the operating system, meaning the malware can act quickly and quietly. By the time a user realizes something is wrong, passwords, account access, and crypto wallets may already be stolen.
Who Is Most at Risk From ClickFix Attacks
ClickFix attacks target both Mac and Windows users, so no operating system is safe. However, some users are more exposed than others.
Everyday users who are unfamiliar with command prompts or Terminal apps are prime targets because they may not recognize suspicious instructions.
Reddit users who click on ads without checking the destination are at risk, especially when the ad appears to come from a legitimate brand like HBO Max.
Remote workers and developers who frequently use terminal commands may be more likely to paste code without scrutiny.
Organizations running fleets of Windows computers face a broader risk if employees fall for these lures.
Companies that run fleets of Windows computers can block access to these features across the entire domain to prevent them from being exploited, per security researcher Kevin Beaumont.
How to Protect Yourself From ClickFix Attacks
Protecting yourself from ClickFix attacks starts with recognizing the warning signs. If a website asks you to copy and paste text into your command prompt or Terminal app, treat it as a red flag.
Never paste commands you do not understand. Legitimate CAPTCHAs and anti-bot checks do not require you to open your terminal.
Verify the source. If an ad claims to be from a major brand, go directly to the official website instead of clicking the ad.
Use security tools. As noted by Ars Technica, a tool for Mac users called BlockBlock can defend against attacks that try to trick Apple users into hacking themselves.
Report suspicious ads. If you see a fake ad on Reddit or another platform, report it so the platform can remove it.
Check your accounts. If you think you may have pasted malicious code, change your passwords and review your logged-in sessions immediately.
The Bigger Picture Behind ClickFix Attacks
ClickFix attacks represent a shift in how cybercriminals operate. Instead of relying solely on technical exploits, they manipulate human behavior. By disguising malicious code as a routine security check, attackers convince users to do the dangerous work themselves.
This approach makes ClickFix attacks harder to detect and harder to stop. Antivirus tools may not flag the activity because the user authorized it. Security teams may not notice until data has already been stolen. And everyday users may not realize they have been compromised until it is too late.
The Reddit and HBO Max campaign shows how quickly these attacks can scale. A single compromised advertising account was enough to post hundreds of fake ads to a major platform. While Reddit locked the account and removed the ads, the incident highlights the importance of platform vigilance and user awareness.
Final Thoughts on ClickFix Attacks
ClickFix attacks are a growing threat that affects both Mac and Windows users. They rely on deception rather than complex hacking techniques, which makes them accessible to a wide range of cybercriminals. The latest campaign involving fake HBO Max ads on Reddit shows just how far-reaching these attacks can become.
Staying safe means staying skeptical. Do not paste code into your terminal just because a website tells you to. Verify ads before clicking. Use available security tools. And if you suspect you have been targeted, act quickly to secure your accounts. ClickFix attacks may be sneaky, but they are not unstoppable when users know what to look for.