LiveLive
SPX7619.9800-1.2800%IXIC26186.4100-1.2100%FTSE10605.3800-1.9100%GOLD4267.3000-0.1100%SILVER62.97000.0800%PLATINUM1750.0000-0.0600%PALLADIUM1300.00000.0000%BRENT102.6700-4.6100%DJI52421.2000-1.8600%WTI104.07001.5500%NDX29127.1600-1.4100%NATGAS2.89001.8700%BTC76886.0000-1.2200%RUT2892.2400-2.8000%VIX17.82008.2600%ETH2474.1700-1.8600%DAX25222.9900-3.0200%BNB716.6100-0.9200%XRP1.40000.8100%CAC408046.8800-1.3500%NKY63484.1000-2.5500%DOGE0.0800-1.8200%HSI24667.2400-2.5700%ADA0.2000-2.8300%NIFTY23175.4500-1.0900%SOL100.6300-0.8500%AAPL333.08004.1000%SENSEX74168.9700-0.8000%MSFT505.41001.1400%TASI10792.8600-0.7900%IBOV185500.88000.1900%GOOGL349.39003.2300%TSLA358.97001.3800%MERVAL3084547.20001.6500%TSX35702.5300-2.2200%USD/PKR277.21000.0200%ASX2008672.5000-2.7800%EUR/PKR320.2200-0.6000%STI5638.6400-2.2300%GBP/PKR374.0400-0.1800%SAR/PKR73.88000.0400%FBMKLCI1679.2100-2.0500%AED/PKR75.55000.0900%SET1578.8000-0.7700%KOSPI6627.2600-4.7100%USD/EUR0.87000.7800%TWSE45511.4900-3.5400%GASOLINE3.2100-5.4900%HEATOIL4.9200-2.7400%COPPER6.3700-1.4800%WHEAT721.2500-0.2800%CORN531.00003.3100%SOYBEANS1300.0000-1.2200%COFFEE286.8000-9.0400%COCOA5860.0000-1.6900%SUGAR19.11002.0300%COTTON84.83000.2200%TRX0.3400-0.6300%AVAX7.51001.8600%LINK11.39000.2000%DOT0.9900-2.0800%LTC52.5400-2.3600%SHIB0.0000-0.8000%TON1.3400-0.6000%XLM0.19004.8400%HBAR0.08001.3900%SUI0.7100-1.8500%APT0.5800-1.2800%UNI6.57004.2900%PEPE0.0000-0.0600%NEAR2.4000-0.2700%ARB0.1300-1.8300%OP0.10004.2900%MATIC0.13000.0000%INJ6.0000-0.8900%FIL0.8900-10.7800%ICP2.5900-6.5300%STX0.00000.0000%ETC7.4200-2.8800%ALGO0.0900-1.4200%VET0.0100-6.9400%THETA0.1900-5.7900%FTM0.03000.0000%SAND0.0300-1.0500%MANA0.0700-2.8600%AXS0.9300-1.2300%GALA0.0000-1.7200%CRV0.3400-1.4300%MKR1441.6900-0.3400%AMZN253.5400-1.9200%NVDA210.9600-8.4200%META665.60007.9200%NFLX80.32002.6500%AMD493.41003.3200%AVGO344.7200-3.6800%JPM350.1300-2.3700%V375.28000.0600%MA574.4200-0.8300%XOM165.08003.5200%CVX212.17001.7100%KO89.35001.4500%PEP136.3400-0.9400%DIS108.59003.1100%BA210.2700-0.9300%BABA109.2300-3.5400%JD27.2600-3.5400%PDD79.3800-3.4400%NIO3.6700-3.4200%SPY760.8800-1.2100%QQQ709.1800-1.3600%DIA524.4900-1.8000%IWM287.9100-2.7400%GLD392.8400-3.4200%SLV56.8400-4.9800%TLT80.9300-1.5600%HYG78.5300-0.8000%LQD104.3000-1.1200%XLF57.0300-1.8400%XLK184.2800-1.6000%XLE64.53000.7300%XLV167.7500-2.1600%SMH541.5000-4.5000%ARKK84.7200-1.7400%EEM65.9900-3.9400%IBIT44.7400-1.0800%QAR/PKR76.10000.3200%INR/PKR2.8900-1.5800%JPY/PKR1.79000.7800%CAD/PKR199.5700-0.4000%AUD/PKR197.7000-1.0300%NZD/PKR159.9800-1.8800%MYR/PKR67.8800-0.9800%THB/PKR8.3300-1.0500%EUR/USD1.1500-0.7700%GBP/USD1.3500-0.5200%USD/JPY154.95000.9600%USD/CHF0.82001.0900%AUD/USD0.7100-1.2900%USD/CAD1.39000.9100%NZD/USD0.5800-1.5500%USD/INR95.94001.1800%USD/CNY6.7000-0.1400%USD/HKD7.84000.0300%USD/SGD1.27000.6400%USD/KRW1362.78001.7600%USD/TRY48.63000.3500%USD/ZAR16.32001.9600%USD/MXN17.17001.5600%USD/BRL5.15001.2000%USD/RUB84.2000-1.9200%USD/NGN1317.1200-0.2900%USD/EGP52.04002.0600%USD/KES129.40000.7500%USD/BDT123.47003.5800%USD/LKR329.63003.2100%USD/IDR17685.00000.5500%USD/THB33.27001.1600%USD/MYR4.08000.6900%USD/PHP62.79000.6200%USD/VND25984.00000.0400%USD/ILS3.05001.3700%USD/SAR3.76003.0200%USD/AED3.67000.0400%USD/QAR3.6400-0.1400%USD/KWD0.3100-0.4900%USD/BHD0.3800-0.0300%USD/OMR0.39000.4700%SPX7619.9800-1.2800%IXIC26186.4100-1.2100%FTSE10605.3800-1.9100%GOLD4267.3000-0.1100%SILVER62.97000.0800%PLATINUM1750.0000-0.0600%PALLADIUM1300.00000.0000%BRENT102.6700-4.6100%DJI52421.2000-1.8600%WTI104.07001.5500%NDX29127.1600-1.4100%NATGAS2.89001.8700%BTC76886.0000-1.2200%RUT2892.2400-2.8000%VIX17.82008.2600%ETH2474.1700-1.8600%DAX25222.9900-3.0200%BNB716.6100-0.9200%XRP1.40000.8100%CAC408046.8800-1.3500%NKY63484.1000-2.5500%DOGE0.0800-1.8200%HSI24667.2400-2.5700%ADA0.2000-2.8300%NIFTY23175.4500-1.0900%SOL100.6300-0.8500%AAPL333.08004.1000%SENSEX74168.9700-0.8000%MSFT505.41001.1400%TASI10792.8600-0.7900%IBOV185500.88000.1900%GOOGL349.39003.2300%TSLA358.97001.3800%MERVAL3084547.20001.6500%TSX35702.5300-2.2200%USD/PKR277.21000.0200%ASX2008672.5000-2.7800%EUR/PKR320.2200-0.6000%STI5638.6400-2.2300%GBP/PKR374.0400-0.1800%SAR/PKR73.88000.0400%FBMKLCI1679.2100-2.0500%AED/PKR75.55000.0900%SET1578.8000-0.7700%KOSPI6627.2600-4.7100%USD/EUR0.87000.7800%TWSE45511.4900-3.5400%GASOLINE3.2100-5.4900%HEATOIL4.9200-2.7400%COPPER6.3700-1.4800%WHEAT721.2500-0.2800%CORN531.00003.3100%SOYBEANS1300.0000-1.2200%COFFEE286.8000-9.0400%COCOA5860.0000-1.6900%SUGAR19.11002.0300%COTTON84.83000.2200%TRX0.3400-0.6300%AVAX7.51001.8600%LINK11.39000.2000%DOT0.9900-2.0800%LTC52.5400-2.3600%SHIB0.0000-0.8000%TON1.3400-0.6000%XLM0.19004.8400%HBAR0.08001.3900%SUI0.7100-1.8500%APT0.5800-1.2800%UNI6.57004.2900%PEPE0.0000-0.0600%NEAR2.4000-0.2700%ARB0.1300-1.8300%OP0.10004.2900%MATIC0.13000.0000%INJ6.0000-0.8900%FIL0.8900-10.7800%ICP2.5900-6.5300%STX0.00000.0000%ETC7.4200-2.8800%ALGO0.0900-1.4200%VET0.0100-6.9400%THETA0.1900-5.7900%FTM0.03000.0000%SAND0.0300-1.0500%MANA0.0700-2.8600%AXS0.9300-1.2300%GALA0.0000-1.7200%CRV0.3400-1.4300%MKR1441.6900-0.3400%AMZN253.5400-1.9200%NVDA210.9600-8.4200%META665.60007.9200%NFLX80.32002.6500%AMD493.41003.3200%AVGO344.7200-3.6800%JPM350.1300-2.3700%V375.28000.0600%MA574.4200-0.8300%XOM165.08003.5200%CVX212.17001.7100%KO89.35001.4500%PEP136.3400-0.9400%DIS108.59003.1100%BA210.2700-0.9300%BABA109.2300-3.5400%JD27.2600-3.5400%PDD79.3800-3.4400%NIO3.6700-3.4200%SPY760.8800-1.2100%QQQ709.1800-1.3600%DIA524.4900-1.8000%IWM287.9100-2.7400%GLD392.8400-3.4200%SLV56.8400-4.9800%TLT80.9300-1.5600%HYG78.5300-0.8000%LQD104.3000-1.1200%XLF57.0300-1.8400%XLK184.2800-1.6000%XLE64.53000.7300%XLV167.7500-2.1600%SMH541.5000-4.5000%ARKK84.7200-1.7400%EEM65.9900-3.9400%IBIT44.7400-1.0800%QAR/PKR76.10000.3200%INR/PKR2.8900-1.5800%JPY/PKR1.79000.7800%CAD/PKR199.5700-0.4000%AUD/PKR197.7000-1.0300%NZD/PKR159.9800-1.8800%MYR/PKR67.8800-0.9800%THB/PKR8.3300-1.0500%EUR/USD1.1500-0.7700%GBP/USD1.3500-0.5200%USD/JPY154.95000.9600%USD/CHF0.82001.0900%AUD/USD0.7100-1.2900%USD/CAD1.39000.9100%NZD/USD0.5800-1.5500%USD/INR95.94001.1800%USD/CNY6.7000-0.1400%USD/HKD7.84000.0300%USD/SGD1.27000.6400%USD/KRW1362.78001.7600%USD/TRY48.63000.3500%USD/ZAR16.32001.9600%USD/MXN17.17001.5600%USD/BRL5.15001.2000%USD/RUB84.2000-1.9200%USD/NGN1317.1200-0.2900%USD/EGP52.04002.0600%USD/KES129.40000.7500%USD/BDT123.47003.5800%USD/LKR329.63003.2100%USD/IDR17685.00000.5500%USD/THB33.27001.1600%USD/MYR4.08000.6900%USD/PHP62.79000.6200%USD/VND25984.00000.0400%USD/ILS3.05001.3700%USD/SAR3.76003.0200%USD/AED3.67000.0400%USD/QAR3.6400-0.1400%USD/KWD0.3100-0.4900%USD/BHD0.3800-0.0300%USD/OMR0.39000.4700%
GuruAlpha
GuruAlpha

এক্সপ্লোর

হোমটুলস

ভাষা

Reddit HBO Max Ad Scam: How ClickFix Forces Users to Hack Themselves
Technology

Reddit HBO Max Ad Scam: How ClickFix Forces Users to Hack Themselves

Cybercriminals are abusing Reddit ads and fake video errors to trick Mac and Windows users into running malicious PowerShell scripts on their own machines.

GA

GuruAlpha News Desk

GuruAlpha News Desk

4 min read
ShareXFacebookWhatsApp

ClickFix is an emerging cyberattack tactic where hackers trick users into executing malicious code on their own Windows or Mac devices using copied terminal commands. Disguised as routine error fixes—such as a broken HBO Max video stream on Reddit—these scams bypass traditional security filters by convincing victims to manually paste and execute infostealing malware scripts.

A deceptive advertisement for HBO Max on Reddit did not try to exploit a zero-day vulnerability in Google Chrome or Safari. Instead, it relied on a far simpler mechanism: asking the target to fix a technical glitch themselves. When users clicked the promo link, they were routed to a landing page displaying a convincing streaming failure alert. To resolve the issue, the prompt instructed victims to press a key combination, launch their operating system command terminal, and paste a pre-copied line of text.

By hitting Enter, victims personally executed an encoded script that downloaded password-stealing payloads, effectively turning their own administrative privileges against them. Security analysts track this technique as "ClickFix," a rapidly expanding threat vector that merges aggressive search engine optimization, paid ad placements, and clever psychological manipulation.

The Mechanics of a Self-Inflicted System Breach

Traditional malware distribution relies on silent browser exploits, malicious software installers, or weaponized email attachments. Security platforms have become adept at quarantining unauthorized downloads and flagging suspicious executable files. ClickFix sidesteps these defensive barriers entirely by removing the automated download step.

The attack chain relies on three distinct stages:

  • The Hook: Malicious actors buy ad inventory on high-traffic platforms like Reddit, disguised as legitimate promotional material for streaming services, software updates, or online games.
  • The Deception: Clicking the ad opens a window with a fake error modal—frequently styled as an unexpected WebGL failure or modern DRM verification error.
  • The Trigger: The modal presents a "Copy Error Fix" button. Clicking this button automatically writes a complex Base64-encoded command string to the user's system clipboard while presenting an on-screen visual guide instructing the user to open Windows PowerShell or macOS Terminal and press paste.

Because the command runs directly within the operating system's native command-line interface under the logged-in user's credentials, default security controls frequently treat the operation as a legitimate administrative action.

Exploiting Trust and Administrative Tools

During the early September 2026 campaigns, security researchers tracked multiple variants targeting both major desktop operating systems. On Windows, the clipboard commands invoke PowerShell to silently pull external payloads hosted on compromised cloud infrastructure. On macOS, the scripts utilize terminal commands disguised as system certificate updates to bypass Apple's Gatekeeper protection.

The ultimate goal of these ClickFix deployments is almost universally information theft. Once executed, the command retrieves infostealers such as Lumma Stealer, Vidar, or Atomic macOS Stealer (AMOS). Within seconds, these lightweight programs sweep the host machine for sensitive data, including:

  • Saved browser passwords and cookies
  • Cryptocurrency wallet browser extensions and private keys
  • Session tokens for corporate services like Slack, Discord, and AWS
  • Two-factor authentication backup keys stored in local text files

Ad networks struggle to eliminate these campaigns because the landing pages dynamically alter their behavior. When an automated ad scanner evaluates the link, the page displays a benign product advertisement. Only when an actual desktop browser visits the site does the server deliver the malicious ClickFix interface.

Defending Systems Against Clipboard Social Engineering

Protecting networks from ClickFix requires a combination of strict system policy enforcement and user awareness regarding browser interactions. Since the payload execution relies entirely on manual paste actions, technical controls must focus on limiting user command-line capabilities and monitoring clipboard abuse.

Enterprise IT administrators are countering this vector by enforcing explicit execution policies on command terminals. Disabling unconstrained PowerShell access for non-administrative accounts stops the execution chain immediately. Security teams also deploy Endpoint Detection and Response (EDR) tools configured to flag any instance where PowerShell or macOS Terminal launches directly with encoded web fetch commands.

For individual users, cybersecurity principles remain straightforward: legitimate streaming platforms and websites will never require a user to run terminal commands or open administrative prompts to display content. Any website asking you to press Win + R, paste clipboard text, or execute scripts in Terminal is actively executing an attack against your device.

Frequently Asked Questions

What is a ClickFix cyberattack and how does it compromise devices?

ClickFix is a social engineering attack that tricks users into manually copying and executing malicious command-line scripts disguised as error fixes. By pasting the text into Windows PowerShell or macOS Terminal, users inadvertently bypass OS safety filters to download information-stealing malware.

Why don't standard antivirus programs automatically block ClickFix scripts?

Antivirus tools often miss ClickFix because the attack does not perform an illegal automated download through the browser. Instead, the operation runs through legitimate native system utilities under the logged-in user's explicit administrative commands.

How can users protect themselves from ClickFix scams on sites like Reddit?

Users should never execute terminal commands or run key combinations like Win+R prompted by external websites or media players. Legitimate streaming services and software platforms never require users to manually run system scripts to fix playback issues.

Share this story
ShareXFacebookWhatsApp
GA

GuruAlpha News Desk

The GuruAlpha News team delivers accurate, timely coverage of breaking news, markets, technology, and lifestyle — in English and Urdu.

NewsBreaking

Related Stories

All Technology

More Stories

Home