Security researchers say a rising form of cyber attack known as ClickFix is tricking Mac and Windows users into installing malware on their own computers. The attacks use fake websites, or legitimate sites that have been hacked, to display a message that looks like a CAPTCHA or an anti-bot checkbox.
Once a user clicks, a prompt appears asking them to perform a "check" to proceed. It instructs them to copy and paste a string of text into the Windows command prompt or the Mac Terminal app. As soon as the user hits return, they unwittingly install info-stealing malware capable of immediately stealing passwords, access to logged-in accounts and crypto wallets, according to the evidence.
Because the user is working in the computer's terminal, which lets them interact directly with the operating system using text-based commands, many of these attacks evade antivirus and security defence tools.
Researchers say the latest campaign involved hackers posting fake ads on Reddit that linked to a page resembling HBO Max but containing a ClickFix lure. According to security researchers at Hudson Rock and a thread on Reddit's cybersecurity subreddit, the hackers compromised the official HBO Max account on Reddit and used it to post hundreds of fake but real-looking adverts.
It is unclear how many people clicked on the fake ads or how many were ultimately compromised. Warner Brothers Discovery, which owns HBO, did not respond to a request for comment, and neither did Reddit.
While developers commonly run one-line snippets of code in the terminal, regular users are less likely to use Command Prompt or PowerShell in Windows, or Terminal in macOS. Security researcher Kevin Beaumont notes that companies running fleets of Windows computers can block access to these features across an entire domain to prevent them being exploited. As noted by Ars Technica, a tool for Mac users called BlockBlock can also defend against attacks that try to trick Apple users into hacking themselves.