11 days ago
TechCrunch Sep 14, 2026

ClickFix attacks are tricking Mac and Windows users into hacking themselves

A new wave of cyberattacks called "ClickFix" is rapidly targeting Mac and Windows users by tricking them into unintentionally installing malware on their computers. The attacks typically involve users encountering fake websites or compromised legitimate sites that display deceptive messages resembling CAPTCHAs or anti-bot checks. When users follow prompts to copy and paste a line of code into their system’s Terminal or Command Prompt, believing they are performing a security check, they instead activate harmful malware that can steal sensitive information such as passwords, account access, and cryptocurrency wallets.

The latest notable ClickFix campaign exploited a compromised HBO Max Reddit advertising account, which hackers used to post hundreds of fraudulent ads linking to phishing pages. These pages duped users with convincing fake HBO Max sites instructing them to execute the malicious code. Security researchers from Hudson Rock revealed this attack method and highlighted the scale of deception involved. Reddit confirmed it disabled the compromised advertising account and removed the malicious ads but did not disclose the number of users impacted.

ClickFix attacks uniquely bypass traditional antivirus and security defenses because the malware deployment happens via legitimate terminal commands executed directly by the user. While developers often run code snippets in Terminal for legitimate purposes, everyday users rarely do so, making this technique especially effective in fooling less experienced users. IT administrators can mitigate risks by disabling terminal access across user domains, and certain security tools like Mac’s BlockBlock have been identified as helpful defenses against these unauthorized code executions.

As ClickFix attacks gain traction worldwide, cybersecurity experts urge users to exercise caution when prompted to run commands in their computers’ terminals, especially if the request originates from unexpected sites or advertisements. The covert nature of these operations and reliance on user actions to self-install malware mark a significant evolution in hacking tactics for 2026, underscoring the importance of robust user education and proactive security measures.

0
0 Read source
Share this post
Facebook Twitter LinkedIn

Discussion

0 comments

No comments yet

Start the discussion with a take, question, or market read.