AAPL $331.34 -0.20% ▼ ACN $193.40 +0.03% ▲ ADBE $257.76 -0.28% ▼ ADEA $24.90 +0.36% ▲ ADIG $20.44 +0.44% ▲ ADP $276.53 -0.63% ▼ ADSK $226.50 -0.30% ▼ AEHR $81.58 +0.47% ▲ AEVA $14.19 +0.17% ▲ AGYS $104.64 +0.00% ▲ AI $10.79 -0.19% ▼ AIP $20.41 +0.79% ▲ ALAB $252.54 -0.57% ▼ ALKT $19.25 -2.74% ▼ ALNT $91.28 +0.00% ▲ AMBA $64.33 -0.42% ▼ AMBQ $60.85 +0.08% ▲ AMD $504.20 +0.02% ▲ AMPL $13.37 -0.07% ▼ AMZN $248.42 +0.02% ▲ ANET $192.84 +0.12% ▲ AOSL $24.76 +1.98% ▲ APLD $23.42 -0.72% ▼ APP $331.46 +0.66% ▲ APPN $37.92 -2.42% ▼ APPS $11.38 +0.19% ▲ ARM $241.83 +0.22% ▲ ARRY $4.38 -1.57% ▼ ARW $212.83 -0.21% ▼ ASML $1,591.48 -0.10% ▼ AAPL $331.34 -0.20% ▼ ACN $193.40 +0.03% ▲ ADBE $257.76 -0.28% ▼ ADEA $24.90 +0.36% ▲ ADIG $20.44 +0.44% ▲ ADP $276.53 -0.63% ▼ ADSK $226.50 -0.30% ▼ AEHR $81.58 +0.47% ▲ AEVA $14.19 +0.17% ▲ AGYS $104.64 +0.00% ▲ AI $10.79 -0.19% ▼ AIP $20.41 +0.79% ▲ ALAB $252.54 -0.57% ▼ ALKT $19.25 -2.74% ▼ ALNT $91.28 +0.00% ▲ AMBA $64.33 -0.42% ▼ AMBQ $60.85 +0.08% ▲ AMD $504.20 +0.02% ▲ AMPL $13.37 -0.07% ▼ AMZN $248.42 +0.02% ▲ ANET $192.84 +0.12% ▲ AOSL $24.76 +1.98% ▲ APLD $23.42 -0.72% ▼ APP $331.46 +0.66% ▲ APPN $37.92 -2.42% ▼ APPS $11.38 +0.19% ▲ ARM $241.83 +0.22% ▲ ARRY $4.38 -1.57% ▼ ARW $212.83 -0.21% ▼ ASML $1,591.48 -0.10% ▼

Campaign Using Fake HBO Max Ads on Reddit Fuels Growing “ClickFix” Threat on Mac and Windows

September 14, 2026 · by TPW Pipeline

Campaign Using Fake HBO Max Ads on Reddit Fuels Growing “ClickFix” Threat on Mac and Windows

A social-engineering technique known as “ClickFix” is gaining traction among cybercriminals, with a recent campaign using counterfeit HBO Max advertisements on Reddit to lure both Mac and Windows users into compromising their own devices, according to reporting published this week.

Unlike traditional malware attacks that exploit software vulnerabilities, ClickFix attacks rely on psychological manipulation. Victims are typically shown a convincing error message, verification prompt, or instructional overlay — in this case delivered through deceptive ads on Reddit — and are then guided into running commands themselves, often via the Run dialog, Terminal, or PowerShell. Because the malicious action is executed by the user with their own permissions, the approach can bypass many security tools that focus on detecting exploits rather than human-driven actions.

The tactic underscores how platforms that host user-generated or third-party content, including Reddit, have become vectors for malware distribution through paid and organic content alike. Reddit, which operates a digital community platform across the United States and internationally, trades at $154.46, down 0.86% from its previous close of $155.80, with a market capitalization of roughly $34.88 billion.

The rise of ClickFix also highlights the expanding scope of endpoint-security challenges for software vendors. Microsoft, whose Windows operating system remains a primary target for such schemes and which has published guidance on the technique, has warned that attackers increasingly favor these low-tech approaches because they require no zero-day exploits. Microsoft shares recently traded at $491.65, off 0.32% from a prior close of $493.25, valuing the company at approximately $3.71 trillion.

Security researchers say macOS users, long considered less frequently targeted, are now squarely in the crosshairs as well, with ClickFix-style lures adapted to macOS via shell commands entered in Terminal. The convergence of fake advertising, social platforms, and user-executed commands makes the technique inexpensive to run at scale and difficult to attribute.

Users are generally advised to be skeptical of on-screen prompts instructing them to paste commands, verify that advertisements lead to legitimate domains, and avoid running scripts or terminal commands prompted by pop-ups or support pages.

What to watch

  • Further disclosures from security vendors tracking ClickFix campaigns and attribution of the fake ad infrastructure.
  • Platform-level responses from Reddit and advertising networks regarding fraudulent ad detection and removal.
  • Security updates or guidance from Microsoft and Apple addressing user-executed attack techniques.

Source: original release