TechCrunch·3 min read·medium

ClickFix attacks are tricking Mac and Windows users into hacking themselves

Z
Zack Whittaker
ClickFix attacks are tricking Mac and Windows users into hacking themselves
AI Summary

A new cybersecurity threat called 'ClickFix' is tricking users into manually executing malicious commands on their computers by posing as fake CAPTCHA prompts. Hackers have compromised legitimate accounts, such as HBO Max's Reddit profile, to distribute these ads and install info-stealing malware.

Why it matters

This attack vector bypasses traditional antivirus software by exploiting human trust and direct system access, posing a significant risk to personal data and financial security.

Dive DeeperCreate a free account to unlock

If you clicked on an HBO Max ad on Reddit over the past week, you might want to check your computer for malware.

These so-called “ClickFix” attacks have quickly become one of the rising cybersecurity threats of 2026, and they’re getting both sneakier and compromising people’s devices with greater frequency. Until recently, ClickFix attacks were a rarity, capitalizing on people searching the web for quick tech fixes. They have since evolved into a massive international effort to hack into people’s computers.

The attacks involve fake websites, or legitimate websites that have been hacked, which display a message that appears to look like a CAPTCHA or an anti-bot checkbox. Once clicked, a prompt appears asking the user to perform a “check” to proceed, which gives instructions to copy and paste a string of text into the user’s Windows command prompt or Mac Terminal app.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in