Кибер гэмт хэрэгтнүүд хуурамч зар сурталчилгаа ашиглан Windows болон macOS үйлдлийн системтэй төхөөрөмжүүдийг онилсон аюултай халдлагыг зохион байгуулж байна.
“ClickFix” нэртэй энэхүү халдлагын арга нь хэрэглэгчдийг өөрийн компьютер дээрх терминал эсвэл тушаалын цонх (Command Prompt) ашиглан хортой код хуулж тавихад хүргэдэг. Халдлага үйлдэгчид нь CAPTCHA эсвэл робот шалгах товчлуур мэт харагдах хуурамч цонхыг вэб хуудсууд дээр байрлуулж, хэрэглэгчдийг заавар дагахад уриалдаг байна. Ингэснээр хэрэглэгч өөрийн гараар компьютерын системд хортой програм суулгаж, нууц үг, бүртгэлийн мэдээлэл болон крипто түрийвчээ алдах эрсдэлд ордог.
Хамгийн сүүлийн үеийн судалгаагаар хакерууд Reddit платформ дээрх HBO Max-ын албан ёсны бүртгэлийг эзэмшилдээ авч, олон тооны хуурамч зар сурталчилгаа байршуулсан нь тогтоогджээ. Энэ төрлийн халдлага нь үйлдлийн системийн үндсэн тушаалын хэрэгслүүдийг ашигладаг тул ихэнх вирусны эсрэг хамгаалалтын программ хангамжуудаас нуугдаж чаддаг байна.
Кибер аюулгүй байдлын шинжээч Кевин Бомонт байгууллагуудад эрсдэлээс сэргийлэхийн тулд сүлжээний хэмжээнд терминал болон PowerShell-д хандах эрхийг хязгаарлахыг зөвлөж байна. Мөн Mac хэрэглэгчид “BlockBlock” зэрэг хамгаалалтын хэрэгслийг ашиглан энэ төрлийн халдлагаас сэргийлэх боломжтой юм. Одоогоор энэ халдлагын улмаас хэчнээн хэрэглэгч хохироод байгаа нь тодорхойгүй байна.
Дэлгэрэнгүйг эх сурвалжаас харах
↓Эх сурвалжийг нээх ↓
If you clicked on an HBO Max ad on Reddit over the past week, you might want to check your computer for malware.
These so-called “ClickFix” attacks have quickly become one of the rising cybersecurity threats of 2026, and they’re getting both sneakier and compromising people’s devices with greater frequency. Until recently, ClickFix attacks were a rarity, capitalizing on people searching the web for quick tech fixes. They have since evolved into a massive international effort to hack into people’s computers.
The attacks involve fake websites, or legitimate websites that have been hacked, which display a message that appears to look like a CAPTCHA or an anti-bot checkbox. Once clicked, a prompt appears asking the user to perform a “check” to proceed, which gives instructions to copy and paste a string of text into the user’s Windows command prompt or Mac Terminal app.
As soon as the user hits return, they unwittingly and instantly install info-stealing malware on their computer, capable of immediately stealing their passwords, access to their logged-in accounts, and crypto wallets. Since the user is working in the computer’s terminal, which lets them interact directly with the operating system using text-based commands, many of these attacks evade antivirus and security defense tools.
Security researchers now say that the latest ClickFix campaign they’ve seen involved hackers posting fake ads on Reddit, linking to a page that looks like HBO Max, but contains a ClickFix lure that tricks people into hacking themselves. The hackers compromised the official HBO Max’s account on Reddit that was then used to post hundreds of fake but real-looking adverts to the news-sharing site, according to security researchers at Hudson Rock and a thread on Reddit’s cybersecurity subreddit.
It’s unclear how many people clicked on these fake ads or how many were ultimately compromised as a result. Warner Brothers Discovery, which owns HBO, did not respond to a request for comment; neither did Reddit.
While it’s typical for developers to run one-line snippets of code in their computer’s terminal, it’s less common for regular users to use the Command Prompt or PowerShell in Windows, or the Terminal in macOS. Companies that run fleets of Windows computers can block access to these features across the entire domain to prevent them from being exploited, per security researcher Kevin Beaumont.
As noted by Ars Technica, a tool for Mac users called BlockBlock can also defend against attacks that try to trick Apple users into hacking themselves.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

