ClickFix Scams Tricking Mac & Windows Users Into Inviting Malware

A clever new attack dubbed “ClickFix” has emerged in 2026, fooling both Mac and Windows users into compromising their own devices. By impersonating tech support prompts and CAPTCHA-like screens, these tricks coax victims into running malicious commands that install malware straight onto their machines. Once inside, these programs steal passwords, hijack accounts, and empty crypto wallets—all without triggering most security tools.

How ClickFix Works

The attack typically starts with a user clicking on a seemingly harmless ad—sometimes on Reddit or other websites—that leads to a page asking them to verify they’re not a bot. It might mimic legitimate login or video streaming sites, and display what looks like a CAPTCHA or anti-bot checkbox. After the user clicks through, another prompt appears: instructing them to run a command in Terminal on macOS or Command Prompt/PowerShell on Windows. By copying and pasting a string, they inadvertently install malicious software.

The HBO Max Twist & Platform Involvement

The latest variant involves fake HBO Max advertisements posted via a compromised official account on Reddit. These ads linked to phony pages with ClickFix prompts, luring users to install info-stealing malware by executing commands on their system. Reddit has seen hundreds of such ads, which researchers believe were posted under the guise of legitimate content by attackers having breached account credentials. It’s not yet clear how many users fell victim.

Unlike power users and developers—who might be accustomed to running commands in their OS—the average user typically doesn’t use Terminal or PowerShell. That gap in familiarity is what attackers are exploiting. Since these operations are performed in environments trusted by the system, they often bypass traditional defense mechanisms.

Defenses & Best Practices

Security experts recommend vigilance when encountering requests to execute commands from websites. Users should never copy-paste terminal instructions from untrusted sources—especially ones accessed via ads or unexpected prompts. Businesses managing many devices can disable access to Terminal or PowerShell to prevent wide-scale exploitation.

Mac users have additional tools like BlockBlock, which can intervene when illusions like ClickFix try to push users into running dangerous commands. Some antivirus solutions and browser sandboxing frameworks may also catch these attacks—but only if the user doesn’t press the confirm key themselves.

These attacks represent a shift in threat models: not phishing via deceptive login pages, but social engineering at the OS level—tricking users into installing malware themselves.

What this means: ClickFix shows how threat actors are now using command-line self-infection as a vector—attacks that many protections overlook. If enough users fall prey, this could become an epidemic. Companies need to lock down endpoints; users must adopt skepticism towards any unexpected prompt. Watch for further escalations of this attack model, where deeper system access is manipulated and user trust abused.