ClickFix attacks are tricking Mac and Windows users into hacking themselves

ClickFix attacks are tricking Mac and Windows users into hacking themselves

A wave of “ClickFix” attacks has emerged, targeting both Mac and Windows users who click on counterfeit HBO Max advertisements posted on Reddit. Security researchers from Hudson Rock and ADAMnetworks discovered that hackers hijacked the official HBO Max Reddit account to disseminate hundreds of fake ads that lead to malicious pages. These pages display a faux CAPTCHA or anti‑bot checkbox; when users click it, a prompt instructs them to copy a string of text into their system’s command line—Windows Command Prompt/PowerShell or macOS Terminal. Executing the command instantly installs information‑stealing malware capable of harvesting passwords, logged‑in accounts and cryptocurrency wallets, while evading many traditional antivirus solutions because the infection occurs via legitimate terminal commands.

The campaign illustrates a shift from earlier, rare ClickFix incidents that preyed on users searching for quick tech fixes to a coordinated, international effort exploiting trusted platforms. By compromising a legitimate brand’s Reddit presence, attackers increase the credibility of their lures, making ordinary users more likely to follow the instructions. Because the malicious code runs directly in the operating system’s shell, it bypasses typical security defenses; however, enterprise administrators can mitigate the risk by disabling terminal access across their domains, as suggested by researcher Kevin Beaumont. For macOS users, the open‑source tool BlockBlock offers additional protection against scripts that attempt to coerce users into running harmful commands.

The extent of the damage remains uncertain, as neither Warner Brothers Discovery—the owner of HBO—nor the affected Reddit community have provided figures on clicks or successful compromises. Researchers have posted details on Reddit’s cybersecurity subreddit, but the lack of official comment leaves the scope of the breach ambiguous. The incident underscores the growing sophistication of social‑engineering attacks that weaponize everyday command‑line interfaces, prompting both individuals and organizations to reassess how they secure terminal access and verify the authenticity of online advertisements.

Sources cited: 📰 TechCrunch ↗

⚡ Effects Interpreter

🌍World Economy

  • Markets around the world might take their cue from how this story unfolds.
  • Trade and investment between countries could shift a little if things escalate.

🏙️Local Economy

  • Jobs and trade close to home might feel a soft knock-on effect.
  • The high street usually mirrors big-picture shifts, just a little later.

🏦Rates & Banks

  • Savers might glance at their account rate — lenders adjust after big events.
  • Any move in rates would probably come later, not overnight.

❤️Health

  • Looking after mental health is worth it when headlines feel heavy.
  • The strain, if any, tends to show up subtly in everyday life.

💷Wealth

  • Nest eggs can wobble briefly before finding their footing again.
  • Long-term savers usually ride out these small bumps just fine.

🏠Housing

  • Mortgage deals could edge around if lenders read the wider mood.
  • Buyers and renters could notice only a gentle drift, if anything at all.
Share: 𝕏 Twitter Facebook LinkedIn WhatsApp

Editorial note: This analysis was produced by the News Effects Interpreter, an AI editorial tool that cross-references 1 independent news sources and contextualises events in terms of their real-world impact on ordinary people. Original reporting is linked above. News Effects does not alter the facts of source reports.