HBO Max Reddit Ads Spread ClickFix Malware to Mac and Windows Users
Hackers hijacked HBO Max’s Reddit ad account to spread ClickFix malware, tricking Mac and Windows users into exposing passwords, accounts and crypto wallets.
Summary
During the week before September 14, 2026, hackers hijacked HBO Max’s official Reddit advertising account and posted hundreds of convincing ads linking to a fake HBO Max page. Hudson Rock researchers and Reddit’s cybersecurity community identified the campaign. Reddit locked the account and removed the malicious ads but disclosed neither how many users were targeted nor how many clicked. Total infections remain unknown, and Warner Brothers Discovery, HBO’s owner, did not comment.
The page used ClickFix, a fast growing 2026 threat that has expanded from rare scams targeting searches for quick technical fixes into an international hacking effort. A fake CAPTCHA or anti-bot check instructed Windows users to paste commands into Command Prompt or PowerShell, or Mac users into Terminal. Pressing return installed information stealing malware capable of immediately taking passwords, logged in accounts and crypto wallets. Direct operating system commands can evade antivirus and other defenses. Kevin Beaumont said companies can block terminal access across Windows domains, while BlockBlock can protect Macs. Developers routinely run one-line terminal commands, but ordinary users rarely need to do so.
Positives
- Reddit locked the compromised HBO Max account and removed the malicious advertisements.
- Hudson Rock researchers and Reddit’s cybersecurity community identified the ClickFix campaign.
- Companies can block Command Prompt, PowerShell and other terminal access across managed Windows domains, Kevin Beaumont said.
- BlockBlock can help defend Mac users against attempts to install malware through deceptive commands.
Risks & concerns
- Hundreds of fake HBO Max advertisements appeared through a compromised official Reddit account during the week before September 14, 2026.
- ClickFix malware can immediately steal passwords, logged in accounts and crypto wallets from Mac and Windows computers.
- Commands pasted directly into Terminal, Command Prompt or PowerShell can evade antivirus and other security defenses.
- Reddit disclosed neither the number of targeted users nor clicks, while the total number of compromised devices remains unknown.
- ClickFix has expanded from a rare technical support lure into a fast growing international hacking effort during 2026.