ClickFix Attacks Trick Mac and Windows Users via Reddit Ads
A new wave of 'ClickFix' cyberattacks is targeting Mac and Windows users through fake advertisements on Reddit. Hackers compromised an official HBO Max account authorized to run ads on Reddit, using it to post malicious adverts that linked to a fake HBO Max page. The page displayed a fake CAPTCHA, instructing users to copy and paste a malicious command into their Terminal (Mac) or Command Prompt (Windows). This action installs info-stealing malware that can exfiltrate passwords, session cookies, and crypto wallets. Security firm Hudson Rock reported on the campaign, and Reddit has since locked the compromised account and removed the malicious ads, though the number of affected users remains unclear. The attack exploits user trust in legitimate brands and the power of terminal commands.
