ClickFix Attack Alert: Fake HBO Max Reddit Ads Are Hijacking Mac and Windows Users

TL;DR
- Fake HBO Max ads on Reddit are redirecting users to lookalike streaming sites that push a ClickFix prompt urging them to copy-paste a "fix" to watch video.
- The trick works on both Windows and Mac, silently running PowerShell or Terminal commands that install password stealers, remote access trojans, and crypto hijackers.
- If you ran the command, disconnect from the internet, kill unknown processes, run a full antivirus scan, and change all passwords from a clean device immediately.
A New Twist On An Old Streaming Trap
If you've been hunting for a free way to watch HBO's biggest shows on Reddit, stop and look twice before you click. Security researchers are warning of an active campaign using sponsored-looking Reddit posts and comments advertising free HBO Max streams that lead straight to a ClickFix infection.
Instead of exploiting a software bug, this attack convinces you to hack yourself. The fake streaming page looks almost identical to Max, complete with show art, play buttons, and a loading spinner. When you hit play, you don't get video — you get a fake playback error.
That error is the trap.
How The Self-Hack Scam Actually Works
ClickFix is a social-engineering technique that exploded over the past year because it's brutally simple and bypasses most antivirus tools.
Here's the flow seen in the HBO Max Reddit campaign:
- The lure: A Reddit ad or promoted post promises "Watch HBO Max Free in 4K - No Signup" with trending titles like House of the Dragon, The Last of Us, and Euphoria. Some posts hijack legitimate streaming discussion threads.
- The redirect: Clicking takes you off Reddit to domains like hbomax-streaming[.]live, max-watchfree[.]online, or play-maxhd[.]net. These sites are freshly registered and rotate every few days to avoid blocklists.
- The fake fix: The site shows a CAPTCHA check or a pop-up that says "Video Cannot Load - Click Fix & Press Allow" or "Verify You Are Human To Continue Watching." Clicking the button copies a malicious command to your clipboard.
On Windows, victims are told to press Windows + R, paste, and hit Enter. That command typically launches PowerShell or mshta.exe to silently download malware in the background. On Mac, victims are told to open Terminal via Spotlight, paste, and hit Enter, often with instructions disguised as installing a "video codec" or "HD player update."
In both cases, the user sees nothing happen — while infostealers are installed in seconds.
Why Both Mac And Windows Users Are At Risk
This campaign is notable because it targets both operating systems with tailored payloads, something researchers say is becoming the new standard for ClickFix.
Windows victims are most commonly hit with Lumma Stealer, Vidar, and NetSupport RAT. These steal browser passwords, cookies, crypto wallets, Discord and Telegram sessions, and give attackers remote access.
Mac victims, who long believed they were immune, are being hit with Atomic macOS Stealer (AMOS) and fake update packages. Once installed, the malware harvests Keychain passwords, browser data, crypto wallets, and system information, then sends it to attacker-controlled servers.
Who is most at risk? Anyone searching Reddit for free streams, cheap Max accounts, or early episode leaks. Young streamers, cord-cutters, and users without active ad-blockers or endpoint protection are prime targets. Because Reddit ads blend in with normal posts, even cautious users are getting fooled.
Red Flags To Watch For Before You Paste Anything
Legitimate streaming services will never ask you to do any of these things. Treat it as an instant red flag if a site asks you to:
- Press Windows + R, open PowerShell, Terminal, or Run dialog and paste a command
- Click "Fix," "Verify," or "I'm Not A Robot" and then copy something to your clipboard
- Install a codec pack, video player update, or browser extension to watch a show
- Disable antivirus or allow manual commands to fix a playback error
Also check the URL carefully. The real Max service lives at max.com. Anything with extra words like max-free, hbomax-player, or strange extensions like .live, .top, or .online is fake. If Reddit comments are disabled on the ad post or filled with generic bot replies like "Works great thanks!", walk away.
Infected? Critical Steps To Detect And Remove The Malware
If you followed the instructions and pasted the command, assume you are compromised. Act fast:
Disconnect and Don't Log In: Disconnect from Wi-Fi immediately to cut off data exfiltration. Do not log into banking, email, or crypto from the infected machine.
Check For Infection Signs: On Windows, open Task Manager and look for strange PowerShell, mshta.exe, or wscript.exe processes, plus new startup programs or scheduled tasks you didn't add. On Mac, check Activity Monitor for unknown processes, look in System Settings > General > Login Items, and Applications folder for apps you didn't install.
Wipe And Scan: Run a full scan with Windows Defender plus a second-opinion scanner like Malwarebytes. On Mac, use Malwarebytes for Mac or CleanMyMac X-Ray, then delete malicious profiles in System Settings > General > Device Management. In many cases, security experts recommend a full OS reinstall for ClickFix infections because stealers can leave persistence mechanisms.
Lock Down Your Accounts: From a clean device, change passwords for email, banking, Apple ID / Microsoft account, social media, and crypto wallets. Revoke active sessions, enable two-factor authentication everywhere, and check for email forwarding rules attackers may have added. If you entered card details, freeze your card and monitor for fraud.
Report It: Report the Reddit ad as Malicious / Spam, report the fake domain to Google Safe Browsing, and let your bank know if financial data was exposed.
The Bigger Picture: Why ClickFix Keeps Winning
Security teams say ClickFix works because there's no malicious file to detect until the user runs it themselves. It abuses trusted Windows and macOS tools, so traditional antivirus often stays silent.
Reddit is an ideal distribution channel because attackers can buy ad space, spoof popular subreddits like r/streaming, r/cordcutters, and r/HBOMAX, and target users already looking to bend the rules.
The takeaway is simple: there is no free HBO Max 4K stream that requires you to open Terminal or PowerShell. If a site tells you to fix your own player, close the tab, block the advertiser, and warn others.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!