ClickFix attacks are tricking Mac and Windows users into hacking themselves
- ID
- 24295
- Status
- summarized
- Published
- 15 Sep 2026, 2:08 AM
- Fetched
- 15 Sep 2026, 3:43 AM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/09/14/clickfix-attacks-are-tricking-mac-and-windows-users-into-hacking-themselves/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 6.5
- Created
- 15 Sep 2026, 3:43 AM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
ClickFix attacks have escalated in 2026, using fake CAPTCHA or anti-bot prompts on compromised or fake websites to trick users into pasting malicious commands into Windows Command Prompt or Mac Terminal, installing info-stealing malware that grabs passwords, session tokens, and crypto wallets. The latest campaign hijacked HBO Max's official Reddit account to post hundreds of fake ads linking to a lookalike page with the ClickFix lure.
Why it matters
Because the malware runs via the user's own terminal, it often evades antivirus—so standard endpoint defenses won't save you. Train yourself and your team to never paste anything into Terminal or Command Prompt from a web prompt, and treat any 'verify you are human' flow that asks for clipboard paste as an immediate red flag.
Discussion angle
How to set up a simple guardrail—like disabling clipboard paste in Terminal or using a canary token—so that even non-technical teammates can't accidentally self-infect via ClickFix lures.