A ClickFix attack linked to a compromised HBO Max Reddit account targeted both Windows and macOS users. Advertising directed people to a deceptive page that attempted to persuade them to install malware themselves.
How the HBO Max ClickFix attack unfolded
The incident was reported on 15 September 2026 and centred on an HBO Max account on Reddit that had been compromised. The trusted identity was then used as part of a malware delivery campaign, demonstrating how an established social media presence can be turned against its audience after an account takeover.
According to the report, advertisements led users to a ClickFix page. Rather than relying only on the automatic exploitation of a software flaw, the page used social engineering to convince visitors to take actions that would result in malware being installed on their computers.
The reported attack path involved several distinct stages:
- An HBO Max Reddit account was compromised by an attacker.
- The account was used to direct or expose users to malicious content.
- Advertisements led potential victims to a ClickFix page.
- The page presented instructions intended for Windows or macOS users.
- Users who followed those instructions risked installing malware on their own devices.
The available report does not identify how the Reddit account was initially taken over. It also does not state whether stolen credentials, phishing, session theft or another method was responsible. These details are important for determining the original point of compromise, but they had not been disclosed in the source material.
Advertising formed part of the delivery route
Advertising was a key part of this ClickFix attack. Ads provided the route to the malicious page, allowing the campaign to place deceptive content in front of users who might not otherwise visit an attacker-controlled website.
The report does not name the advertising platform, describe the adverts or confirm whether they appeared directly through Reddit. It is therefore not possible to establish from the published information whether the compromised account distributed the ads, promoted links associated with them or was used in another part of the same delivery chain.
What is clear is that the combination of a recognisable entertainment brand, a legitimate social platform and advertising could make the route appear more credible. Users may be less suspicious when content seems to come from a familiar account or is presented through a mainstream online service.
How the ClickFix attack targeted Windows and macOS
The malicious page was designed to target both Windows and macOS users. No specific operating system versions or device models were listed, so organisations should not interpret the report as applying only to a particular release of either platform.
This is significant because the ClickFix attack was based on user action rather than a disclosed vulnerability with a defined list of affected versions. The malicious page attempted to persuade visitors to perform installation steps, meaning exposure depended on whether a user reached the page and followed its instructions.
ClickFix campaigns typically disguise malicious instructions as a solution to a fabricated technical problem. In this incident, the source confirms that users were tricked into installing malware, but it does not publish the exact wording of the prompts, commands presented to victims or installation sequence.
The lack of those technical details limits conclusions about the payload. The malware family, its capabilities, persistence methods and command infrastructure were not identified in the supplied report. There is also no confirmed information about whether the Windows and macOS paths delivered the same malware or separate platform-specific payloads.
Why user interaction was central
The ClickFix attack depended on persuading a person to complete actions that appeared legitimate. This approach can bypass the user’s initial suspicion because the installation may look like a repair, verification or access step rather than a conventional software download.
Unlike an exploit that silently compromises a device, this delivery method inserts the victim into the execution chain. Security warnings may also be less effective if the instructions actively encourage the user to approve prompts or disregard alerts as part of the supposed fix.
However, reaching the page did not necessarily mean that malware was installed. Based on the available information, successful compromise required the visitor to engage with the instructions. The report does not provide victim numbers, infection totals or evidence about how many users viewed the ads.
Current status of the ClickFix attack
The incident was publicly reported on 15 September 2026. The source does not state when the HBO Max Reddit account was first compromised, how long it remained under attacker control or when the malicious advertising activity began.
It also does not confirm whether the account had been recovered, whether the ads had been removed or whether the ClickFix page remained accessible at the time of publication. Without those details, the current exploitation status cannot be established beyond the reported use of the account and advertisements in the campaign.
No indicators of compromise, malicious domains, file hashes or command and control addresses were included in the supplied information. No vulnerability identifier was associated with the incident because the reported method relied on social engineering rather than a named software vulnerability.
The scope should therefore be described carefully. Windows and macOS users were targeted, but the report does not establish that every version of either operating system was compromised. It confirms a cross-platform delivery attempt, not universal infection.
Why the compromised Reddit account matters
The HBO Max Reddit account gave the campaign a trusted public identity that an attacker-created profile would not possess. This can increase the likelihood that users will engage with posts, links or associated advertising before questioning their legitimacy.
The incident also shows how social media account compromise and malicious advertising can support the same ClickFix attack. Brand account security is therefore relevant not only to reputation but also to preventing trusted channels from becoming part of a malware delivery route.
What organisations should do now
Organisations should warn Windows and macOS users not to follow technical instructions delivered through Reddit posts, online adverts or unexpected web pages. Any page that asks a user to run commands, approve an installation or bypass a security warning should be treated as suspicious and reported internally.
- Review endpoint alerts involving unexpected installers or user-initiated command execution after visits to Reddit or advertising links.
- Check managed devices for malware detections associated with recent browser activity.
- Secure organisational Reddit and social media accounts with strong authentication, restricted administrator access and active session reviews.
- Preserve relevant browser, DNS and endpoint logs if a user recalls following instructions from the campaign.
- Block confirmed campaign domains or files if reliable indicators are subsequently published.
Response teams should avoid assuming that macOS devices were outside the campaign’s scope. The reported ClickFix attack explicitly targeted users of both major desktop platforms.
Originally reported by SecurityWeek.







