Hackers Exploit Reddit Ads in Sophisticated "ClickFix" Malware Campaign
A recent surge in "ClickFix" attacks a growing cybersecurity threat in 2026 has targeted users through deceptive ads on Reddit, tricking victims into installing malware on their own devices. Security researchers at Hudson Rock and ADAMnetworks, along with reports from Reddit’s cybersecurity community, revealed that hackers compromised an official HBO Max Reddit ad account to post hundreds of fake but convincing advertisements.
The malicious ads directed users to a spoofed HBO Max page, where they encountered a fake CAPTCHA or anti-bot prompt. Upon clicking, victims were instructed to copy and paste a command into their Windows Command Prompt or macOS Terminal, which instantly deployed info-stealing malware. The malware could harvest passwords, logged-in session data, and cryptocurrency wallet credentials, bypassing traditional antivirus defenses by exploiting terminal-based execution.
Reddit confirmed the breach, stating that the compromised HBO Max ad account was locked and the malicious ads removed, though the company did not disclose how many users were affected. Warner Bros. Discovery, HBO’s parent company, did not respond to requests for comment.
While terminal-based attacks are more common among developers, security experts warn that blocking access to Command Prompt, PowerShell, or Terminal across corporate networks can mitigate risks. For Mac users, tools like BlockBlock may help prevent such self-inflicted compromises. The full scale of the campaign remains unclear, but the incident highlights the evolving sophistication of social engineering tactics in cybercrime.
Reddit TPRM report: https://www.rankiteo.com/company/reddit-for-business
Warner Bros. Discovery TPRM report: https://www.rankiteo.com/company/warner-bros--entertainment
"id": "redwar1789496892",
"linkid": "reddit-for-business, warner-bros--entertainment",
"type": "Breach",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Streaming Services',
'name': 'HBO Max',
'type': 'Media/Entertainment'},
{'industry': 'Technology',
'name': 'Reddit',
'type': 'Social Media/Advertising Platform'}],
'attack_vector': 'Malicious Advertisements (Malvertising)',
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': 'Yes (Session Data, '
'Credentials)',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Credentials, Session Data, '
'Cryptocurrency Wallet '
'Information'},
'description': "A recent surge in 'ClickFix' attacks has targeted users "
'through deceptive ads on Reddit, tricking victims into '
'installing malware on their own devices. Hackers compromised '
'an official HBO Max Reddit ad account to post fake '
'advertisements directing users to a spoofed HBO Max page. '
'Victims were instructed to copy and paste a command into '
'their Windows Command Prompt or macOS Terminal, which '
'deployed info-stealing malware capable of harvesting '
'passwords, logged-in session data, and cryptocurrency wallet '
'credentials.',
'impact': {'brand_reputation_impact': 'Potential Reputational Damage to HBO '
'Max and Reddit',
'data_compromised': 'Passwords, Logged-In Session Data, '
'Cryptocurrency Wallet Credentials',
'identity_theft_risk': 'High (Credentials Harvested)',
'payment_information_risk': 'High (Cryptocurrency Wallet '
'Credentials)',
'systems_affected': 'User Devices (Windows, macOS)'},
'initial_access_broker': {'entry_point': 'Compromised Reddit Ad Account'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Terminal-based attacks are a growing threat, and blocking '
'access to Command Prompt/PowerShell/Terminal can mitigate '
'risks. Social engineering tactics are becoming more '
'sophisticated.',
'motivation': 'Financial Gain (Data Theft, Cryptocurrency Wallet Credentials)',
'post_incident_analysis': {'root_causes': 'Exploitation of social engineering '
'via malicious ads, lack of '
'terminal access restrictions'},
'recommendations': ['Block access to Command Prompt, PowerShell, or Terminal '
'across corporate networks',
'Use tools like BlockBlock for Mac users to prevent '
'self-inflicted compromises',
'Enhance monitoring of ad platforms for malicious '
'activity'],
'references': [{'source': 'Hudson Rock'},
{'source': 'ADAMnetworks'},
{'source': 'Reddit Cybersecurity Community'}],
'response': {'containment_measures': 'Compromised HBO Max ad account locked, '
'malicious ads removed',
'third_party_assistance': 'Hudson Rock, ADAMnetworks'},
'title': "Hackers Exploit Reddit Ads in Sophisticated 'ClickFix' Malware "
'Campaign',
'type': 'Malware Campaign',
'vulnerability_exploited': 'Social Engineering (Fake CAPTCHA/Anti-Bot Prompt)'}