Cybersecurity researchers are tracking a fast-growing threat known as ClickFix, a tactic that uses convincing fake prompts to push users into running harmful commands on their own devices. What once appeared as isolated scams has now evolved into a broader campaign aimed at Windows and Mac users.
The method is simple but effective: a fake website, or a compromised legitimate one, shows a message that resembles a CAPTCHA or anti-bot check. Users are then told to copy a line of text into the Windows Command Prompt or the macOS Terminal to continue. Once executed, that command can install info-stealing malware designed to collect passwords, account access, and crypto wallet data.
Recent cases have included fake ads on Reddit that led to a page imitating HBO Max. According to security researchers at Hudson Rock, the campaign used a compromised Reddit account to distribute large volumes of deceptive ads. The exact number of affected users remains unclear, but the incident highlights how social engineering is becoming more polished and more scalable.
Experts note that these attacks are especially effective because they exploit trusted system tools. While terminal commands are routine for developers, many everyday users are unfamiliar with them, making the trick harder to recognize. In managed environments, organizations can reduce exposure by limiting access to command-line tools across company devices.
For Mac users, security tools such as BlockBlock can add another layer of defense against suspicious behavior. As ClickFix-style campaigns continue to spread, digital awareness and stronger endpoint controls are becoming essential parts of modern protection. The trend suggests a future where user education and system-level safeguards will work together more closely to keep devices secure.