ELSEIF
Your brief EB
1,046 stories from 222 feeds 1279 clusters Refreshed 20 minutes ago next pull 04:48

PLATFORMS Signal 39

Hackers hijacked HBO Max’s Reddit advertising account to spread ClickFix malware

Compromised HBO Max Reddit ads have been used to lure Mac and Windows users into running malicious terminal commands that install credential-stealing malware.

WHY IT MATTERS

The attack bypasses traditional antivirus by executing directly in the OS shell, giving threat actors immediate access to passwords, logged-in sessions, and crypto wallets. Enterprises that allow terminal use across fleets must consider policy controls, and individual users need to treat any unsolicited command-line prompt as suspicious.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Fake HBO Max ads on Reddit link to pages that mimic CAPTCHAs and request a copy-paste command into the terminal.

02

Executing the command installs info-stealing malware that can harvest credentials and crypto assets.

03

Reddit confirmed the HBO Max ad account was compromised, locked it, and removed the malicious ads.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
TechCrunch ClickFix attacks are tricking Mac and Windows users into hacking themselves Open ↗