ClickFix is giving cybercriminals another way into Windows and Mac computers by getting people to run the malicious code themselves.
What looks like a CAPTCHA, app download or routine technical instruction can lead someone into PowerShell, Windows Run or Mac Terminal. Following the directions can install information-stealing malware directly on the device.
One recent campaign brought the tactic to Reddit after hackers gained control of HBO Max’s verified advertising account. More than 100 malicious ads ran over roughly 48 hours, giving the attack the credibility of a recognizable brand.
Why It Matters: ClickFix takes advantage of tools that many companies already allow employees to use, making command-line access worth another review. PowerShell and Terminal may be necessary for some roles, but that access can also give a malicious web page a direct route to execute code. Companies may need tighter permissions and better visibility into command activity, especially on devices where employees have no reason to use those tools.
- ClickFix Puts the User in the Infection Chain: Attackers disguise their instructions as a CAPTCHA or software installation, then tell the user to open a system tool and paste in a command. Running that command can download and execute malware directly on the computer. PowerShell and Terminal are legitimate tools used by developers and administrators, which can help malicious activity get past defenses focused on suspicious downloads or executable files.
- HBO Max Gave the Attackers a Trusted Account: Hackers compromised HBO Max’s verified Reddit advertising account and used it to run more than 100 malicious ads in about two days. One advertised what appeared to be an HBO Max app for macOS. Others promoted AI tools and developer software to reach people outside the streaming service’s audience. Reddit confirmed the account was compromised, locked it and removed the ads. The number of people who clicked or were infected remains unknown.
- PasteSwitch Can Adapt the Attack to the Computer: Researchers connected the activity to a cross-platform campaign called PasteSwitch. Windows users can receive instructions involving PowerShell or other built-in tools, while Mac users can be directed to Terminal. Researchers observed MacSync and an AMOS-related information stealer in the campaign. Other versions have posed as cryptocurrency wallet applications designed to capture recovery phrases.
- One Infection Can Expose Workplace Access: Malware delivered through ClickFix has been observed targeting browser credentials and macOS passwords along with information stored in applications such as Telegram and Apple Notes. An infected work computer could also contain saved credentials or active sessions for company systems. That gives stolen browser and account data value even after the original infection is discovered.
- Operating Systems Are Adding New Barriers: Apple added protections in macOS Tahoe 26.4 aimed at this type of attack. Macs can warn users when text copied from a browser is pasted into Terminal, while XProtect can inspect the resulting activity and block known malicious commands. Companies managing Windows fleets can restrict command-line tools when employees do not need them. Those measures can make ClickFix harder to execute, although attackers can continue changing the instructions used to persuade people to run the commands.
Hackers hijack HBO Max Reddit account to spread malware – Bitedefender


