Back Ground.News Hackers Hijack HBO Max's Reddit Account to Spread Malware via 108 Fake Ads
Security researchers said hundreds of fake ads lured users to paste commands that installed info-stealing malware.
Security researchers identified ClickFix as a rising 2026 cybersecurity threat, utilizing fake CAPTCHA prompts to trick users into compromising their own devices.
Upon clicking, a prompt instructs users to copy and paste a string of text into their Windows Command Prompt or Mac Terminal to proceed with a fake check.
Hitting return instantly installs info-stealing malware that compromises passwords, logged-in accounts, and crypto wallets as part of a massive international effort to hack into computers.
Companies can block access to these features across their domain to prevent exploitation, while Mac users can employ BlockBlock tool, according to security researcher Kevin Beaumont and Ars Technica.
HBO Max's Account Was Hijacked to Spread Malware
The incident underscores how ClickFix-style attacks are increasingly being used to trick users into installing malware on their computers.
ClickFix attacks are tricking Mac and Windows users into hacking themselves
If you clicked on a fake HBO Max ad on in the past week, you might have fallen victim to a rising 'ClickFix' security threat.
Hackers hijack HBO Max account to push malware in ClickFix ads
Hackers compromised HBO Max's official account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.
Using Official Accounts, ClickFix Type Attack Has Spread Across
Cyber attacks known as ClickFix quickly became one of the most frequent security threats — and, more than that, the invaders
Hackers hijack HBO Max account to push malware in ClickFix ads | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker - National Cyber Security Consulting
Hackers Hijack HBO Max Account to Spread ClickFix Malware
Hackers used a compromised HBO Max advertising account on to spread ClickFix malware, tricking users into running commands that could steal sensitive data.
67 % of the sources lean Left
To view factuality data please Upgrade to Premium
To view ownership data please Upgrade to Vantage
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
