Fake HBO Max Ads Spread ClickFix Malware on Reddit: This Week in Scams

If a website asks you to open Terminal, PowerShell, Command Prompt, or the Windows Run box and paste something in, stop.

That simple rule can protect you from a type of attack McAfee has been tracking for years. Known as ClickFix, the scam turns an ordinary-looking online instruction into a way for criminals to install malware on your device. The lure might look like a CAPTCHA, a software fix, a download, or a quick tutorial. The trick is getting you to run the attack yourself.

ClickFix is back in the headlines this week after attackers reportedly compromised HBO Max’s verified Reddit advertising account and used it to distribute malicious ads. But while the brands, websites, and platforms keep changing, the underlying trick is one McAfee researchers have been following since at least 2024.

Introducing McAfee+

Full-service identity and credit protection now in one plan

What is a ClickFix Attack?

A ClickFix attack is a social engineering scam that convinces someone to copy, paste, or run a malicious command on their own computer.

This week’s example shows why the tactic can be so convincing. According to TechCrunch, attackers compromised an HBO Max account authorized to run ads on Reddit. The account was then used to publish malicious advertisements that could direct people to fake sites, including pages made to look like they were associated with HBO Max.

Researchers investigating the campaign reported finding 108 malicious ads posted over roughly 48 hours. Some promoted what appeared to be a Mac version of HBO Max, while others used software and AI-related lures.

Instead of providing a normal download, the sites instructed visitors to open tools such as Terminal on a Mac or PowerShell or the Run dialog on Windows, paste in a command, and execute it. That last step is the important one.

The website is not really helping you fix or install something. It is convincing you to give your computer malicious instructions.

Depending on the campaign and device, those instructions can lead to information-stealing malware designed to collect things such as saved passwords, browser information, account data, or cryptocurrency wallet information.

Reddit told TechCrunch that it learned an HBO Max account authorized to run advertisements had been compromised and used for malicious links. The company said it locked the account and removed the ads. The number of people who clicked the ads or were ultimately compromised remains unclear.

How McAfee Has Been Tracking ClickFix for Years

What makes this week’s story notable isn’t that ClickFix suddenly appeared. It’s how far the tactic has traveled.

McAfee Labs documented ClickFix attacks in July 2024 after researchers discovered compromised websites displaying fake error messages that instructed people to paste scripts into PowerShell. Researchers observed the technique being used to deliver malware including DarkGate and Lumma Stealer.

Just a few months later, McAfee Labs documented another variation built around something nearly everyone recognizes: the CAPTCHA.

Victims encountered fake “Verify you are a human” or “I’m not a robot” pages. Clicking the button could copy a malicious command to the clipboard. The page would then walk the person through opening the Windows Run box and pasting it in. McAfee researchers observed those fake CAPTCHA attacks connected to phishing emails and searches for cracked games.

By 2025, the same basic idea was appearing in yet another familiar place: social media tutorials. McAfee reported on ClickFix-style scams circulating through TikTok videos that promised free software upgrades or premium versions of popular apps. Instead of solving a problem, the instructions could lead people to install information-stealing malware.

Now the lure has changed again. This time, attackers allegedly used advertising from a compromised, verified corporate account.

That evolution matters because ClickFix isn’t one particular fake website or pop-up you can memorize. It’s a reusable scam technique.

Why ClickFix Scams Can Be So Convincing

Most online scams ask you to click something. ClickFix adds another layer by asking you to do something.

That action may feel technical enough to be legitimate. A page tells you there’s an error. It gives you several steps to fix it. Maybe you’re asked to press a few keys, open a utility you’ve seen on your computer before, paste something, and hit Enter.

Following instructions can feel safer than downloading an unfamiliar file. But in a ClickFix attack, following the instructions is effectively the download.

Attackers also keep placing these instructions inside familiar online experiences. McAfee researchers have seen fake error messages and CAPTCHA checks. Other campaigns have appeared in social media tutorials, software downloads, phishing messages, and now online advertising.

Even a familiar brand or verified account shouldn’t override an unusual request from a website.

Key Takeaways

ClickFix is a social engineering technique, not one specific scam. The lure can change while the basic attack stays the same.

McAfee researchers have tracked ClickFix campaigns since 2024, including fake error messages and CAPTCHA pages designed to deliver malware.

Mac users aren’t automatically outside the target zone. This week’s campaign reportedly included separate techniques targeting both macOS and Windows.

The biggest warning sign is an unusual instruction. A website should not need you to paste an unexplained command into Terminal, PowerShell, Command Prompt, or Run to prove you’re human or download ordinary consumer software.

How McAfee Helps

You deserve multiple layers of cybersecurity protection to prevent and stop threats like ClickUp at every potential point of malware entry. That’s what McAfee’s built to do.

Web Protection can help prevent access to known malicious websites, including sites used as part of malware campaigns. That matters when an otherwise convincing ad or message sends you somewhere dangerous.

Device Security adds another layer by scanning for and helping block malware that attackers attempt to install. McAfee Labs has previously documented McAfee protections blocking stages of ClickFix infection chains, including malicious URLs and suspicious behavior.

And because information stealers often target passwords and account information, Identity Monitoring can help alert you when monitored personal information is found in a breach so you can respond sooner.

Technology can help, but ClickFix also has a human checkpoint built into the attack. If a webpage suddenly asks you to become your own system administrator and run a command you don’t understand, don’t.

Other Scam and Security News This Week

Spain’s privacy regulator receives report of an alleged AI-powered breach. Spain’s data protection agency said it was notified of an incident in which an AI agent was allegedly used to find vulnerabilities, access systems, probe applications, and ultimately access or modify data. The regulator has not yet investigated and verified the reported incident, an important distinction as security researchers continue examining how AI agents could be misused in cyberattacks.
Source: BleepingComputer

Revolut says its core systems weren’t hacked in customer data incident. Reuters reported that sensitive information involving about 680 customers was disclosed after fraudulent requests were sent from a legitimate government agency email domain, according to a source familiar with the matter. Revolut said it had received no direct demand from the group claiming responsibility, while the group reportedly threatened to sell customer records unless it received a $3 million ransom.
Source: Reuters

More details emerge about the malicious HBO Max Reddit ads. Additional reporting on the ClickFix campaign said the compromised account was used to run 108 malicious ads over about 48 hours, with lures ranging from HBO Max downloads to AI and software tools. The findings reinforce the main lesson from this week’s story: a verified account or recognizable brand doesn’t make unusual download instructions safe.
Source: Malwarebytes

This Week’s Safety Tips

Some practical safety tips in light of this week’s news:

Don’t paste commands from websites into system tools. Treat the request itself as a warning sign.

Skip software downloads promoted through ads. Navigate to the company’s official website or trusted app store yourself.

Use multifactor authentication on important accounts. It can provide another barrier if a password is stolen.

Keep security protection and your devices updated. Current protection gives you more opportunities to catch malicious sites and malware before they can do damage.

ClickFix may keep changing its disguise, but you don’t need to learn every version. Remember the underlying trick: a website that asks you to copy, paste, and run unfamiliar commands is asking for far more trust than you should give it.

And we’ll be back next week with more cybersecurity news and scam alerts.

FacebookLinkedInTwitterEmailCopy Link

Stay Updated

Follow us to stay updated on all things McAfee and on top of the latest consumer and mobile security threats.

FacebookTwitterInstagramLinkedINYouTubeRSS

More from Security News

Back to top