Static

ClickFix attacks are tricking Mac and Windows users into hacking themselves

First reported by TechCrunch ·

The signal ●○○○ Compiled by AI from TechCrunch, the single source so far
Why you might care

You may unknowingly install malware by following instructions in fake security prompts on websites.

What happened

ClickFix attacks, a rapidly emerging cybersecurity threat in 2026, are increasingly tricking both Mac and Windows users into compromising their own devices. These attacks leverage fake or compromised websites that display deceptive CAPTCHA-like prompts. When users interact with these prompts, they are instructed to copy and paste a command into their system's terminal (Windows Command Prompt or macOS Terminal). Executing this command installs info-stealing malware that can immediately access passwords, logged-in accounts, and cryptocurrency wallets. The use of system terminals allows these attacks to bypass many traditional antivirus and security defenses. A recent campaign involved hackers compromising an official HBO Max Reddit account to post malicious ads, which led to fake HBO Max pages containing ClickFix lures. While the full extent of compromise is unknown, Reddit has since locked the compromised account and removed the malicious ads. Security measures like blocking terminal access on Windows or using tools like BlockBlock on Mac can offer defense.

What it means

The evolution of ClickFix attacks highlights a growing trend in social engineering, where threat actors exploit user trust and urgency by impersonating legitimate services or appearing as necessary security measures. The bypass of traditional defenses by operating within system terminals is a significant concern, indicating a need for more sophisticated endpoint detection and response mechanisms that monitor system-level activity. This sophisticated phishing vector, disguised as a technical fix, requires users to exercise extreme caution with any command-line instructions they encounter, even when presented on seemingly trusted platforms like Reddit.

This development poses a direct challenge to current cybersecurity strategies, pushing the boundaries of what constitutes a successful exploit by weaponizing user interaction with core operating system tools. Companies with large fleets of computers now face an increased risk, making the implementation of granular security policies that restrict or monitor terminal usage paramount. For individual users, the reliance on OS-level defenses or specialized tools like BlockBlock becomes more critical, as standard antivirus may prove insufficient against these terminal-based attacks.

AI-written summary. May contain errors.