Tech news in 3 minutes
ClickFix attacks are tricking Mac and Windows users into hacking themselves
Hackers are using a compromised HBO Max Reddit account to spread "ClickFix" malware attacks, a rapidly growing cybersecurity threat in 2026 that tricks users into infecting their own computers. This SEO-focused news summary covers the latest ClickFix campaign, targeting readers searching for cybersecurity threats, Reddit ad malware, and info-stealing attacks. According to security researchers at Hudson Rock and a Reddit cybersecurity subreddit, attackers hijacked HBO Max's official Reddit account to post hundreds of fake advertisements. These ads linked to a page mimicking HBO Max but containing a ClickFix lure. ClickFix attacks present a fake CAPTCHA or anti-bot checkbox; when clicked, users are instructed to copy and paste a text string into their Windows Command Prompt or Mac Terminal. Hitting return instantly installs info-stealing malware that can steal passwords, logged-in accounts, and crypto wallets. Because the attack executes directly in the operating system's terminal, it often evades antivirus and security defenses. Reddit confirmed to TechCrunch that an HBO Max ad account was compromised and used to run malicious ads. The company locked the account and removed the ads but did not disclose how many users were targeted or clicked. Warner Bros Discovery, HBO's owner, did not respond to a comment request. Security experts recommend blocking access to Command Prompt and Terminal in enterprise environments (per researcher Kevin Beaumont) and using tools like BlockBlock for Mac to defend against such attacks. The incident underscores the evolution of ClickFix from a rarity to a massive international hacking effort.