A recent surge in ClickFix attacks has raised concerns among cybersecurity experts as hackers use fake HBO Max advertisements on Reddit to deceive users into installing malware. These attacks involve misleading websites that prompt users to copy and paste commands into their Windows Command Prompt or macOS Terminal. Once executed, the commands install malware that can steal passwords, account credentials, and cryptocurrency wallets.

The latest campaign exploited a compromised HBO Max Reddit account to post hundreds of fraudulent ads linking to deceptive pages. These pages mimic legitimate sites but include prompts resembling CAPTCHAs, which instruct users to perform a "check" by entering specific commands. Because the malware installation occurs through the terminal interface, it often evades detection by antivirus and other security software.

Reddit confirmed the compromise of the HBO Max advertising account, which was subsequently locked and had the malicious ads removed. However, the platform has not disclosed how many users were exposed or affected by the campaign. Warner Brothers Discovery, HBO Max's parent company, did not respond to requests for comment.

Security professionals note that while developers commonly use terminal commands, typical users rarely do, making this attack vector particularly effective. Organizations managing Windows devices can mitigate risk by restricting access to command-line tools across their networks. Mac users can benefit from security tools like BlockBlock, which help prevent unauthorized terminal-based attacks.

This evolving ClickFix threat highlights the importance of user awareness and cautious behavior when interacting with unexpected prompts online, especially those requesting command-line actions.