Technology News

ClickFix Scams Spread Through Hijacked HBO Max Reddit Ads, Researchers Say

Person at a dimly lit desk looking at two open laptops showing a checkbox page

Anyone who clicked an HBO Max advert on Reddit in the past week should check their machine for malware, according to a report from Techcrunch. Researchers at Hudson Rock, along with a thread on Reddit’s cybersecurity subreddit, say hackers took control of HBO Max’s official Reddit account and used it to post hundreds of adverts that looked genuine but carried a “ClickFix” lure.

The lure is a page that mimics a CAPTCHA or an anti-bot checkbox. After the box is clicked, it asks for a “check” to continue and gives step-by-step instructions to copy a line of text and paste it into the Windows command prompt or the Mac Terminal app. Pressing return installs info-stealing malware immediately, with no further prompt. Because the pasted command runs in the terminal, which interacts directly with the operating system, many of these lures slip past antivirus and other security tools.

Also read: Massachusetts orders large data centers to supply clean power or pay into ratepayer fund

Key facts

  • Hackers compromised HBO Max’s official Reddit account and used it to post hundreds of fake but real-looking adverts.
  • Hudson Rock and a thread on Reddit’s cybersecurity subreddit are the cited sources for the campaign.
  • The malware is described as info-stealing, capable of taking passwords, access to logged-in accounts and crypto wallets.
  • It is unclear how many people clicked the fake ads or how many were ultimately compromised.
  • Warner Brothers Discovery, which owns HBO, did not respond to a request for comment; Reddit did not either.

A fast-growing 2026 threat

ClickFix attacks were once a rarity, mostly capitalising on people searching the web for quick technical fixes. Techcrunch reports they have since grown into a large international effort to break into computers, and that they are becoming both more deceptive and more frequent.

The Reddit case shows how far the technique has travelled from its origins. Instead of standing up a fresh domain and hoping for search traffic, the operators leaned on a trusted account and a familiar brand to reach users inside a platform they already use. The adverts pointed at a page styled to resemble HBO Max before presenting the fake verification step.

Also read: Instagram Now Lets You Add Tagged Posts Directly to Your Profile Grid

Where the defence sits

Running one-line code snippets in a terminal is routine for developers. It is far less common for ordinary users to touch Command Prompt or PowerShell on Windows, or Terminal on macOS, which is what the lures depend on.

Security researcher Kevin Beaumont said organisations that manage fleets of Windows computers can block access to those features across an entire domain, cutting off the technique at the point of execution. Ars Technica noted that Mac users can turn to a tool called BlockBlock to defend against attacks that try to talk Apple users into compromising their own machines.

Why it matters

The campaign matters because it targets credential stores and crypto wallets rather than simply hijacking a browser session, and because the entry point was a verified account on a mainstream site rather than an obvious scam domain. Anyone on Reddit in the past week who tapped an HBO Max ad should treat their logins and wallet access as potentially exposed, particularly if they pasted anything into a terminal afterwards. The broader shift is one of method: ClickFix turns the victim into the person who runs the malicious command, which is why conventional antivirus signatures often miss it.

What to watch

Two things will shape the story from here. Reddit and Warner Brothers Discovery have not yet commented, so responses from either platform would clarify how the account was taken over and what users should expect. And because the number of people who clicked or were compromised remains unknown, any tally from Hudson Rock or the affected companies would set the scale of what is currently an uncounted incident.

Neelima Kumar

Written by

Neelima Kumar

Neelima Kumar covers technology and artificial intelligence for StockPil, tracking how emerging tech trends intersect with markets and business.

Reported by techcrunch.com.


Warning: Attempt to read property "term_id" on false in /www/wwwroot/stockpil.com/wp-content/themes/flex-mag/functions.php on line 998
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

To Top