Science & Technology

Cybersecurity Alert: Fake HBO Max ad on Reddit leads to ClickFix attacks targeting Windows and Mac devices.

Story Highlights
  • ClickFix attacks have surged in 2026, posing serious cybersecurity threats.
  • A fake HBO Max ad on Reddit led to the dissemination of ClickFix malware.
  • Users unknowingly execute commands, allowing attacks to bypass traditional security measures.
  • Cybersecurity experts advise blocking access to Command Prompt and using protective tools on macOS.

ClickFix attacks have escalated to become one of the most dangerous cybersecurity threats in 2026. A new global campaign exploits a fake advertisement for HBO Max on the Reddit platform, prompting users to compromise their own devices.

How Do ClickFix Attacks Work?

The attack relies on deceiving users through fake websites or compromised legitimate sites, presenting a seemingly normal CAPTCHA verification box. After users click on it:

  • A message appears requesting a “check” or an additional step.
  • Users are directed to copy and paste code commands into the Windows Command Prompt or macOS Terminal.
  • Once they press Enter, malware installs, capable of stealing passwords, login data, and cryptocurrency wallets.

The danger lies in the fact that users execute the command themselves, allowing the attack to bypass traditional security software.

Hacking of HBO Max Account on Reddit

Cybersecurity researchers at Hudson Rock confirmed that attackers compromised the official HBO Max account on Reddit, authorized to post advertisements. They used this account to disseminate hundreds of fake ads leading to ClickFix pages. Reddit acknowledged the breach and removed the ads but did not disclose the number of affected users.

Why Is the Attack Hard to Detect?

  • Executing commands in Terminal or PowerShell is unusual for the average user.
  • Social engineering tricks the victim into believing they are performing a normal technical step.
  • Commands execute directly within the system, making detection more challenging for antivirus software.

How to Protect Yourself?

For Windows Users:

  • Company administrators can block access to Command Prompt and PowerShell at the network level.

For macOS Users:

  • Utilize the BlockBlock tool, which monitors attempts to install malware.

Conclusion of the Scene

ClickFix attacks reveal a dangerous shift in the tactics of cybercriminals: the breach no longer relies on complex technical vulnerabilities but instead on convincing users to click, copy, and execute.

The post Cybersecurity Warning: Fake HBO Max Advertisement on Reddit Leads to ClickFix Attacks Targeting Windows and Mac Devices appeared first on Yemen TV.

To follow the news in Arabic

Via
Yemen TV

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Developed by ​Infragate Solutions LTD