Hackers compromised HBO Max's verified Reddit account and posted 108 malicious ads using ClickFix social engineering to distribute information-stealing malware to Windows and macOS users. The campaign, linked to a broader operation called PasteSwitch, tricked victims into pasting commands into their terminals to install fake applications, including counterfeit HBO Max apps and cryptocurrency wallets.
ClickFix attacks are deceiving Mac and Windows users through fake ads on Reddit, including a compromised HBO Max account, by displaying fake CAPTCHA prompts that trick users into pasting malware code into their terminal, instantly installing info-stealing malware that can access passwords and crypto wallets.
Thousands of legitimate small-business websites have been compromised to distribute malware through fake CAPTCHA prompts that trick users into running Windows commands. Netskope identified over 5,400 compromised sites across 2,200 organizations, with attackers using blockchain infrastructure to hide malicious instructions and evade detection.
ClickFix attacks, which use fake CAPTCHA overlays and terminal commands on compromised websites, have become mainstream malware distribution techniques affecting both PC and Mac users. Attackers exploit user fatigue from legitimate security prompts and complex interfaces, making the malicious instructions appear routine. The technique's simplicity and effectiveness have led even Kremlin-backed groups to adopt it.
ClickFix attacks, which use fake CAPTCHA overlays on compromised websites to trick users into running malicious terminal commands, have become mainstream and are infecting both PC and Mac users at scale. The technique's effectiveness stems from widespread internet fatigue, as casual users have grown desensitized to complex instructions and suspicious-seeming security prompts. Even Kremlin-backed hacking groups have adopted the method.