Key facts
- ClickFix attacks are a growing cybersecurity threat in 2026.
- The attacks trick users into installing info-stealing malware via terminal commands.
- A recent campaign used compromised HBO Max Reddit ads to lure victims.
- The malware can steal passwords, account access, and crypto wallets.
- The attacks evade antivirus by operating in the command prompt or terminal.
- Companies can block terminal access to prevent exploitation.
Cybersecurity researchers are warning of a sophisticated phishing technique dubbed "ClickFix" attacks that trick users into inadvertently installing malware on their Mac and Windows computers. These attacks have rapidly evolved and are becoming more frequent, posing a significant threat.
The method involves presenting users with fake websites or compromised legitimate sites that display messages resembling CAPTCHA or anti-bot verification checks. Upon clicking, users are instructed to copy and paste a string of text into their system's command prompt (Windows) or Terminal app (macOS). Executing this command instantly installs info-stealing malware, which can then access passwords, logged-in accounts, and cryptocurrency wallets. The use of the terminal bypasses many standard antivirus and security defenses because it allows direct interaction with the operating system.
