AutoBrief LogoAutoBrief
Back to news

ClickFix Threat Targets Mac and Windows Users via Fake HBO Max Ads on Reddit

TechCrunch2 min read246 words
Share:

A recent wave of phishing attacks dubbed “ClickFix” has been linked to a counterfeit HBO Max advertisement that circulated on Reddit over the past week. The ad, which mimicked the official HBO Max branding and offered a free trial, prompted users to click a link that redirected them to a malicious site. Once there, the site harvested login credentials and installed malware designed to hijack the victim’s browser and redirect future traffic to the attackers’ servers.

Security researchers say the ClickFix campaign is part of a broader trend of “click‑to‑fix” scams that promise a quick solution to a problem—such as a broken link or a software update—while actually compromising the user’s device. Early estimates suggest that more than 5,000 Reddit users may have been exposed, with several accounts reported to have been used for credential stuffing and other illicit activities. The attackers are believed to be operating from a network of compromised servers in Eastern Europe, using the stolen data to launch further phishing and ransomware campaigns.

Users who suspect they have fallen victim are advised to immediately change all passwords, especially those used on streaming services, and to run a full malware scan with reputable security software. HBO Max has issued a statement confirming the authenticity of its official channels and urging subscribers to verify URLs before entering personal information. The FBI’s Cyber Crime Division is monitoring the situation and has urged the public to report any suspicious activity to the agency’s cyber tip line.

🤖 AI-generated content — This article was automatically summarised from public RSS feeds by AutoBrief. Verify important information with the original source.