15 Sept 2026, 08:57 AM 3 min readtech

ClickFix Social Engineering Attacks Trick Mac and Windows Users Into Installing Malware

Cybersecurity researchers are sounding alarms over a rapidly spreading wave of social engineering threats known as ClickFix attacks, which trick Mac and Windows users into executing malicious terminal commands themselves. The campaign has recently surfaced on mainstream platforms, including Reddit, where attackers compromised an official corporate account to distribute deceptive advertisements.
Unlike traditional malware vectors that rely on exploiting software vulnerabilities or downloading stealthy payloads, ClickFix campaigns manipulate users through deceptive user interfaces. Victims encounter fake websites or compromised legitimate pages displaying fraudulent CAPTCHA or anti-bot verification windows. When users attempt to complete the purported check, they are instructed to copy and paste a string of text into their Windows command line or macOS Terminal app.

The Mechanics of User-Executed Infection

Once a user executes the pasted text string within their system terminal, info-stealing malware is instantly deployed. Because the commands are executed directly through native administrative utilities such as Windows Command Prompt, PowerShell, or the macOS Terminal app, many of these attacks successfully bypass standard antivirus software and perimeter security tools.
Security researchers point out that the technique eliminates the need for cybercriminals to build complex network infrastructure or rotate command-and-control domains. By leveraging the user's own administrative access, the malware immediately targets sensitive data, including stored passwords, active session cookies for logged-in accounts, and cryptocurrency wallets.

Compromised Advertising Accounts and Platform Response

The most recent wave identified by security analysts at Hudson Rock involved fake advertisements posted on Reddit. Attackers managed to compromise the official HBO Max corporate account on the platform, utilizing it to broadcast hundreds of deceptive advertisements featuring ClickFix lures.
Reddit confirmed the security breach to TechCrunch, stating that the company "recently learned that an HBO Max account authorized to run advertisements on Reddit was compromised and used to run ads containing malicious links." Reddit officials confirmed that the affected account was locked and the fraudulent ads removed, though the company declined to disclose the exact number of users targeted or compromised.

Advanced Threat Actors and Defense Strategies

Security analysts emphasize that the ClickFix technique is no longer restricted to opportunistic cybercriminals. Sophisticated operations, including state-sponsored groups from Russia and other advanced persistent threat actors, have integrated the method into broader campaigns, deploying fake CAPTCHA prompts inside Google Sheets documents and blockchain-based smart contracts.
Security researcher Kevin Beaumont noted that business organizations operating within Windows environments can mitigate prompt-based threats by enforcing strict group policies that disable Start and Run prompt functionality for standard user groups, though such measures are rarely deployed universally. For Apple users, specialized utilities such as BlockBlock can help defend against deceptive scripts designed for macOS terminals.

Sources & Citations

Reporting basis: multiple publisher reports; this is not independent verification.

The Indus Pulse is committed to accuracy and transparency.