Click Fix3 mins read

ClickFix Attacks Target Mac and Windows Users Through Fake HBO Max Ads on Reddit

TechCrunch reports that a ClickFix campaign used fake HBO Max ads on Reddit to trick Mac and Windows users into running malicious commands on their own computers.

What happened

TechCrunch reports that a recent ClickFix campaign used fake HBO Max ads on Reddit to lure Mac and Windows users into compromising their own devices. The article says users who clicked an HBO Max ad on Reddit over the past week may want to check their computers for malware.

According to the report, the campaign involved an HBO Max account authorized to run Reddit ads that was compromised and used to post ads containing malicious links. Reddit told TechCrunch it locked the account and removed the ads.

How ClickFix tricks users

ClickFix attacks use fake websites, or legitimate websites that have been hacked, to show prompts that look like CAPTCHAs or anti-bot checks. After a user clicks, the page instructs them to copy and paste text into Windows Command Prompt, PowerShell, or the Mac Terminal app.

Once the user runs the command, TechCrunch reports the malware can immediately steal passwords, access logged-in accounts, and target crypto wallets. Because the user is running commands directly in the terminal, the report says many of these attacks can evade antivirus and other security tools.

What remains unclear

The scale of the campaign is not known. TechCrunch reports that it is unclear how many people clicked the fake ads or how many were compromised.

Warner Brothers Discovery, which owns HBO, did not respond to TechCrunch’s request for comment. Reddit also did not say how many users were targeted or clicked the malicious ads when asked.

Practical takeaways for users and companies

Do not paste commands from a website, ad, CAPTCHA-style prompt, or login page into your terminal or command prompt unless you fully understand and trust the source. A request to run a command just to “verify” or “proceed” should be treated as a major warning sign.

For organizations, TechCrunch notes that companies managing fleets of Windows computers can block access to command-line tools across a domain to reduce exposure. The report also points to BlockBlock as a defensive tool for Mac users against attacks that try to trick Apple users into running malicious actions themselves.

Discover More