Should you clicked on an HBO Max advert on Reddit over the previous week, you would possibly wish to test your pc for malware.
These so-called “ClickFix” assaults have rapidly change into one of many rising cybersecurity threats of 2026, they usually’re getting each sneakier and compromising individuals’s units with higher frequency. Till just lately, ClickFix assaults have been a rarity, capitalizing on individuals looking the net for fast tech fixes. They’ve since developed into a large worldwide effort to hack into individuals’s computer systems.
The assaults contain pretend web sites, or official web sites which have been hacked, which show a message that seems to appear like a CAPTCHA or an anti-bot checkbox. As soon as clicked, a immediate seems asking the consumer to carry out a “test” to proceed, which supplies directions to repeat and paste a string of textual content into the consumer’s Home windows command immediate or Mac Terminal app.
As quickly because the consumer hits return, they unwittingly and immediately set up info-stealing malware on their pc, able to instantly stealing their passwords, entry to their logged-in accounts, and crypto wallets. For the reason that consumer is working within the pc’s terminal, which lets them work together instantly with the working system utilizing text-based instructions, many of those assaults evade antivirus and safety protection instruments.
Safety researchers now say that the most recent ClickFix marketing campaign they’ve seen concerned hackers posting pretend adverts on Reddit, linking to a web page that appears like HBO Max however comprises a ClickFix lure that methods individuals into hacking themselves. The hackers compromised the official HBO Max’s account on Reddit that was then used to submit tons of of faux however real-looking adverts to the news-sharing web site, in response to security researchers at Hudson Rock and a thread on Reddit’s cybersecurity subreddit.
It’s unclear how many individuals clicked on these pretend adverts or what number of have been finally compromised consequently. Warner Brothers Discovery, which owns HBO, didn’t reply to a request for remark.
Reddit informed TechCrunch it “just lately realized that an HBO Max account approved to run commercials on Reddit was compromised and used to run adverts containing malicious hyperlinks,” and that the corporate locked the account and eliminated the adverts. When requested, Reddit didn’t say what number of customers have been focused or clicked the malicious adverts.
Whereas it’s typical for builders to run one-line snippets of code of their pc’s terminal, it’s much less frequent for normal customers to make use of the Command Immediate or PowerShell in Home windows, or the Terminal in macOS. Firms that run fleets of Home windows computer systems can block entry to those options throughout the complete area to forestall them from being exploited, per safety researcher Kevin Beaumont.
As famous by Ars Technica, a software for Mac customers known as BlockBlock also can defend in opposition to assaults that attempt to trick Apple customers into hacking themselves.
Up to date with remark from Reddit.
While you buy by means of hyperlinks in our articles, we might earn a small fee. This doesn’t have an effect on our editorial independence.
