ClickFix attacks are tricking Mac and Windows users into hacking themselves

39 minutes ago 1
a screenshot of a fake HBO Max login leafage   showing a ClickFix lure that tries to instrumentality   the unfortunate  into pasting malicious codification  into their computer.Image Credits:Unhappy-Capital-1464 / Reddit

11:08 AM PDT · September 14, 2026

If you clicked connected an HBO Max advertisement connected Reddit implicit the past week, you mightiness privation to cheque your machine for malware.

These alleged “ClickFix” attacks person rapidly go 1 of the rising cybersecurity threats of 2026, and they’re getting some sneakier and compromising people’s devices with greater frequency. Until recently, ClickFix attacks were a rarity, capitalizing connected radical searching the web for speedy tech fixes. They person since evolved into a monolithic planetary effort to hack into people’s computers.

The attacks impact fake websites, oregon morganatic websites that person been hacked, which show a connection that appears to look similar a CAPTCHA oregon an anti-bot checkbox. Once clicked, a punctual appears asking the idiosyncratic to execute a “check” to proceed, which gives instructions to transcript and paste a drawstring of substance into the user’s Windows bid punctual oregon Mac Terminal app. 

As soon arsenic the idiosyncratic hits return, they unwittingly and instantly instal info-stealing malware connected their computer, susceptible of instantly stealing their passwords, entree to their logged-in accounts, and crypto wallets. Since the idiosyncratic is moving successful the computer’s terminal, which lets them interact straight with the operating strategy utilizing text-based commands, galore of these attacks evade antivirus and information defence tools.

Security researchers present accidental that the latest ClickFix run they’ve seen progressive hackers posting fake ads connected Reddit, linking to a leafage that looks similar HBO Max, but contains a ClickFix lure that tricks radical into hacking themselves. The hackers compromised the authoritative HBO Max’s relationship connected Reddit that was past utilized to station hundreds of fake but real-looking adverts to the news-sharing site, according to security researchers astatine Hudson Rock and a thread connected Reddit’s cybersecurity subreddit.

It’s unclear however galore radical clicked connected these fake ads oregon however galore were yet compromised arsenic a result. Warner Brothers Discovery, which owns HBO, did not respond to a petition for comment; neither did Reddit.

While it’s emblematic for developers to tally one-line snippets of codification successful their computer’s terminal, it’s little communal for regular users to usage the Command Prompt oregon PowerShell successful Windows, oregon the Terminal successful macOS. Companies that tally fleets of Windows computers tin artifact entree to these features crossed the full domain to forestall them from being exploited, per information researcher Kevin Beaumont.

As noted by Ars Technica, a instrumentality for Mac users called BlockBlock tin besides support against attacks that effort to instrumentality Apple users into hacking themselves.

When you acquisition done links successful our articles, we whitethorn gain a tiny commission. This doesn’t impact our editorial independence.

Zack Whittaker is the information exertion astatine TechCrunch. He besides authors the play cybersecurity newsletter, this week successful security.

He tin beryllium reached via encrypted connection astatine zackwhittaker.1337 connected Signal. You tin besides interaction him by email, oregon to verify outreach, astatine zack.whittaker@techcrunch.com.

Read Entire Article