If you happen to clicked on an HBO Max advert on Reddit over the previous week, you may wish to verify your pc for malware.
These so-called “ClickFix” assaults have shortly develop into one of many rising cybersecurity threats of 2026, and so they’re getting each sneakier and compromising individuals’s gadgets with higher frequency. Till not too long ago, ClickFix assaults had been a rarity, capitalizing on individuals looking out the net for fast tech fixes. They’ve since developed into an enormous worldwide effort to hack into individuals’s computer systems.
The assaults contain pretend web sites, or reliable web sites which were hacked, which show a message that seems to seem like a CAPTCHA or an anti-bot checkbox. As soon as clicked, a immediate seems asking the consumer to carry out a “verify” to proceed, which provides directions to repeat and paste a string of textual content into the consumer’s Home windows command immediate or Mac Terminal app.
As quickly because the consumer hits return, they unwittingly and immediately set up info-stealing malware on their pc, able to instantly stealing their passwords, entry to their logged-in accounts, and crypto wallets. Because the consumer is working within the pc’s terminal, which lets them work together immediately with the working system utilizing text-based instructions, many of those assaults evade antivirus and safety protection instruments.
Safety researchers now say that the most recent ClickFix marketing campaign they’ve seen concerned hackers posting pretend advertisements on Reddit, linking to a web page that appears like HBO Max however comprises a ClickFix lure that tips individuals into hacking themselves. The hackers compromised the official HBO Max’s account on Reddit that was then used to submit a whole lot of faux however real-looking adverts to the news-sharing website, based on safety researchers at Hudson Rock and a thread on Reddit’s cybersecurity subreddit.
It’s unclear how many individuals clicked on these pretend advertisements or what number of had been in the end compromised in consequence. Warner Brothers Discovery, which owns HBO, didn’t reply to a request for remark.
Reddit advised TechCrunch it “not too long ago realized that an HBO Max account approved to run commercials on Reddit was compromised and used to run advertisements containing malicious hyperlinks,” and that the corporate locked the account and eliminated the advertisements. When requested, Reddit didn’t say what number of customers had been focused or clicked the malicious advertisements.
Whereas it’s typical for builders to run one-line snippets of code of their pc’s terminal, it’s much less widespread for normal customers to make use of the Command Immediate or PowerShell in Home windows, or the Terminal in macOS. Corporations that run fleets of Home windows computer systems can block entry to those options throughout the complete area to forestall them from being exploited, per safety researcher Kevin Beaumont.
As famous by Ars Technica, a instrument for Mac customers known as BlockBlock may also defend in opposition to assaults that attempt to trick Apple customers into hacking themselves.
Up to date with remark from Reddit.
While you buy by way of hyperlinks in our articles, we could earn a small fee. This doesn’t have an effect on our editorial independence.