Skip to content
Hackers Hijack HBO Max Reddit Account to Spread ClickFix Malware

Hackers Hijack HBO Max Reddit Account to Spread ClickFix Malware

Mezha September 14, 2026

Prince Harry and Meghan Move Their Children to a New School Over Security Concerns

Zelenskyy urges parliament to secure budget funding and dismiss Prosecutor General Ruslan Kravchenko

Ukrainian People’s Artist Halyna Yablonska Dies After Serious Illness

Prosecutor General’s Office denies suspicion notice for NABU director

Ukraine’s Padel Team Reaches World Championship Main Draw After Beating Hong Kong

Zelenskyy Urges Parliament to Criminalize Fraudulent Call Centers and Dismiss Prosecutor General

Evening Digest: Ukraine and the World — September 14, 2026

Zelenskyy urges Ukraine’s parliament to dismiss Prosecutor General Ruslan Kravchenko

Russian Missile Strike on Izium Injures Four, Including Three Children

Zelensky Urges Ukraine’s Parliament and Government to Secure Budget Funding and Social Payments

Russian Drone Strike Sets Market Pavilions Ablaze in Kharkiv Region

Ukraine’s Government Ends Lesia Karnaukh’s Tenure as Acting Tax Chief

UK Man Admits Drugging and Raping His Wife for More Than 20 Years

Hackers Hijack HBO Max Account to Spread ClickFix Malware

Amazon Prime Video Adds Short News Clips to Compete With TikTok

Kyiv fertility clinic director Ihor Ilyin dies after shooting

Russian Drones Set Agricultural Enterprise Ablaze in Ukraine’s Kharkiv Region

Ninth Ukraine Support Summit Brings American Advocates to Washington

Zelenskyy appoints military surgeon Kostyantyn Humenyuk to lead Ukraine’s Medical Forces

Zelenskyy Awards 278 Ukrainian Defenders, 134 Posthumously

Trump rejects calls to slow AI development, says US has enough controls

Joe Manchin Backs Two Republicans in Senate Races That Could Shape Control of the Chamber

Oil Prices Surge Above $108 as Middle East Disruptions Threaten a Prolonged Energy Shock

xAI Asks US Appeals Court to Block Minnesota AI Image Law

London Tribunal Upholds Crispin Odey’s Financial Industry Ban but Cuts His Fine

Poland Begins Repairs at Shehyni–Medyka Crossing, Rerouting Buses Until 2027

Ukraine Reports Strikes, Prosecutor Vote and New International Support

US Senate Negotiators Weigh AI Safety Bill as Oversight Powers Remain Unclear

Fuel Price Hikes Trigger Syria’s Largest Protests Since Assad’s Fall

iOS 27 Makes Siri More Useful With Smarter Tools and Automations

Volkswagen unveils Mission Efficiency electric prototype with 323 mpg equivalent

Russian Hacker Group Claims DDoS Attack on Norway’s Parliament Website

Ukraine Risks Losing $29.5 Billion in Aid Without Urgent Parliamentary Votes

Ukraine and Costa Rica Black Sea Security and Air Defense

Russia Bans Sulfuric Acid Exports, Citing Domestic Supply Concerns

Shakhtar Beats Chornomorets 2-0 to Join Polissia atop Ukrainian Premier League

British Expert Says Stronger Pressure Could Force the Kremlin to Rethink Its War Strategy

Summer 2026 Becomes the Hottest on Record in the United States

LZ Detector Records Possible Dark Matter Signal, but Scientists Seek Proof

A familiar streaming brand became the cover for a campaign that asked users to perform an unusually risky “security” step. The consequences could reach far beyond one social platform.

As stated by Techcrunch

ClickFix has become one of the most prominent cyberthreats of 2026. The scheme was initially disguised as a tool for solving technical problems, but it later evolved into a widespread method of infecting devices in countries around the world.

How the ClickFix scheme works

The attack begins when a user visits a fake or compromised legitimate website. A window appears on the page imitating a CAPTCHA or an “I’m not a robot” check. The user is then asked to complete a supposedly additional security step: copy the provided text and paste it into the Windows Command Prompt or macOS Terminal.

If the person presses Enter, the command executes malicious code. It can steal passwords, account credentials, active authentication sessions, and information from cryptocurrency wallets. Running the commands through a system terminal also helps some attacks bypass standard antivirus protections.

Malicious HBO Max ads on

confirmed that it had detected the compromise of the HBO Max account. It was used to distribute ads containing malicious links. After the incident was discovered, the account was blocked and the ads were removed.

The exact number of people who clicked the dangerous ads, as well as the number of potentially infected devices, remains unknown. Warner Bros. Discovery, the company that owns HBO, did not on the incident.

Why ClickFix is dangerous for users

For most people, running commands through the Command Prompt, PowerShell on Windows, or Terminal on macOS is not a routine action. That is why a request to paste unknown text into a system tool should be treated as a serious warning sign.

Researcher Kevin Beaumont noted that organizations can centrally restrict access to such tools on Windows work computers. Mac users can use BlockBlock, a tool that helps detect attempts to change system settings.

ClickFix’s key feature is its use of social engineering. Instead of automatically exploiting a vulnerability, attackers persuade the victim to execute a dangerous command, turning them into an unwitting participant in the infection.

Other topics you might like:

Jaguar Land Rover plans to cut 4,000 jobs over two years as Chinese competition, US trade restrictions, electric vehicle demand and a cyberattack pressure its finances.

AI is accelerating cyberattacks through faster phishing, malware creation and social engineering, but experts say people remain the greatest cybersecurity risk.

Scammers are promoting fake GTA 6 demos that install malware and steal browser passwords, cookies, active sessions, and account access.