Cyber warning: ClickFix attacks exploit a fake HBO Max ad on Reddit.

- ClickFix attacks exploit a fake HBO Max ad on Reddit, compromising user devices.
- Users are tricked into executing malicious commands in Command Prompt or Terminal.
- Cybersecurity researchers confirmed the breach of the official HBO Max account on Reddit.
- To protect against attacks, block Command Prompt for Windows users and use BlockBlock for macOS.
Cybersecurity Alert: ClickFix Attacks Exploit Fake HBO Max Ad on Reddit
ClickFix attacks have emerged as one of the most dangerous cybersecurity threats in 2026. A new global campaign has been detected that exploits a fake advertisement for HBO Max on the Reddit platform, tricking users into compromising their own devices.
How Do ClickFix Attacks Work?
The attack relies on deceiving users through fake websites or compromised legitimate sites. It presents a seemingly normal CAPTCHA verification box. After users click on it:
- A message requests a “check” or an additional step.
- Users are directed to copy and paste commands into the Command Prompt on Windows or Terminal on macOS.
- Once they press Enter, malware installs that can steal passwords, login data, and cryptocurrency wallets.
The danger lies in the fact that users execute the commands themselves, allowing the attack to bypass traditional security software.
HBO Max Account Compromised on Reddit
Cybersecurity researchers at Hudson Rock confirmed that attackers compromised the official HBO Max account on Reddit, which is authorized to post advertisements. They used this account to publish hundreds of fake ads leading to ClickFix pages. Reddit acknowledged the breach and removed the ads but did not disclose the number of affected users.
Why Is the Attack Hard to Detect?
- Executing commands in Terminal or PowerShell is unusual for the average user.
- Social engineering tricks the victim into believing they are performing a normal technical step.
- Commands execute directly within the system, making detection more challenging for antivirus software.
How to Protect Yourself
For Windows Users:
- Company administrators can block access to Command Prompt and PowerShell at the network level.
For macOS Users:
- Utilize the BlockBlock tool, which monitors attempts to install malware.
The Current Landscape
ClickFix attacks reveal a dangerous shift in the tactics of cybercriminals: breaches no longer rely on complex technical vulnerabilities but instead on convincing users to click, copy, and execute commands.
The post Cybersecurity Warning: ClickFix Attacks Exploit Fake HBO Max Ad on Reddit appeared first on Yemen TV Channel.
To follow the news in Arabic


