Clicking These Fake HBO Max Ads Can Infect Your Computer
Reddit says an ad account linked to HBO Max was compromised and used to distribute malicious ads, exposing users to a growing type of cyberattack known as ClickFix.
Security researchers at Hudson Rock said the compromised account was used to publish hundreds of convincing HBO Max ads that redirected users to a fake page designed to install information-stealing malware.
How the ClickFix Attack Works
ClickFix attacks typically imitate a CAPTCHA or anti-bot verification page.
After clicking the fake verification prompt, victims are instructed to copy and paste a command into Windows Command Prompt, PowerShell, or macOS Terminal.
Running that command can immediately install malware capable of stealing passwords, authenticated account sessions, and cryptocurrency wallet information.
Because the victim manually executes commands directly through the operating system, some ClickFix attacks can also bypass traditional antivirus protections.
Reddit Infostealer Adverts
byu/Unhappy-Capital-1464 incybersecurity
Official HBO Max Ad Account Was Compromised
Hudson Rock researchers said attackers gained access to an HBO Max account authorized to purchase ads on Reddit.
The account was then used to distribute legitimate-looking advertisements that sent users to malicious websites impersonating HBO Max.
Reddit confirmed the incident to TechCrunch, saying it had learned that an HBO Max advertising account was compromised and used to run ads containing malicious links.
The company said it locked the account and removed the advertisements.
It did not disclose how many people saw, clicked or were compromised by the ads.
Warner Bros. Discovery, HBO’s parent company, did not provide a comment.
ClickFix Attacks Are Becoming More Common
ClickFix attacks were once relatively uncommon and often appeared on websites offering supposed fixes for technical problems.
Researchers say the technique has since evolved into a broader international malware campaign using compromised websites, fake CAPTCHA pages and major advertising platforms.
The attack relies heavily on social engineering rather than exploiting a software vulnerability, effectively convincing victims to run the malicious code themselves.
What Users Can Do
People who recently clicked an HBO Max advertisement on Reddit should be particularly cautious if the page asked them to open a terminal or command-line tool and paste commands.
Security researcher Kevin Beaumont notes that organizations managing large fleets of Windows machines can restrict access to Command Prompt and PowerShell to reduce this risk.
Mac users can also use security utilities such as BlockBlock, which monitors attempts by software to establish persistent access to macOS.
The exact number of victims remains unknown, but Reddit says the malicious ads have now been removed and the compromised advertising account has been secured.
The post Clicking These Fake HBO Max Ads Can Infect Your Computer appeared first on ProPakistani.



