Business / news

ClickFix Scams Push Mac and Windows Users to Install Malware Themselves

A fast-growing class of cyberattack is persuading Windows and Mac users to paste malicious code into their own command terminals, handing over passwords, account access and crypto wallets. Fake HBO Max ads on Reddit are among the lures used in the past week.

The technique, known as ClickFix, relies on fake pages or legitimate sites that have been compromised to display what looks like a CAPTCHA or an anti-bot checkbox. After a visitor clicks it, a prompt appears asking them to complete a "check" before continuing.

That instruction directs the user to copy a string of text and paste it into the Windows command prompt or the Mac Terminal app. Pressing return installs info-stealing malware almost instantly, with no further warning.

The payload is built to grab passwords, access to accounts the victim is already signed into, and cryptocurrency wallets. Because the commands are executed through the operating system's own terminal, the activity slips past many antivirus programs and other security defenses.

ClickFix campaigns were rare until recently, when they largely targeted people searching the web for quick technical fixes. They have since expanded into what researchers describe as a large international effort to break into personal computers, with the attacks becoming stealthier and more frequent.

A recent wave used fake HBO Max advertisements on Reddit as the entry point, meaning anyone who clicked one of the ads in the past week may want to check their machine for malware.

Security guidance to users, as described in the reporting: treat unexpected CAPTCHA-style prompts that ask for terminal commands as hostile, and never paste unsolicited code into a command line.