ClickFix Attacks Trick Mac and Windows Users Into Hacking Themselves
ClickFix attacks use fake CAPTCHAs to make Mac and Windows users install malware; a campaign abused HBO Max ads.
The lures typically appear on fake websites or legitimate websites that have been hacked, displaying a message that looks like a CAPTCHA or an anti-bot checkbox. After a user clicks it, a prompt appears asking the user to perform a check to proceed and gives instructions to copy and paste a string of text into the Windows Command Prompt or the Mac Terminal app. As soon as the user presses return, the malware is installed unwittingly and instantly. Because the user is working in the computer's terminal, which lets them interact directly with the operating system using text-based commands, many of these attacks evade antivirus and security defense tools, TechCrunch reported.
Security researchers at Hudson Rock and a thread on Reddit's cybersecurity subreddit said the latest ClickFix campaign involved hackers posting fake ads on Reddit that linked to a page resembling HBO Max but contained a ClickFix lure. The hackers compromised the official HBO Max account on Reddit and used it to post hundreds of fake but real-looking adverts to the news-sharing site, according to the researchers and the Reddit thread.
It is unclear how many people clicked on the fake ads or how many were ultimately compromised as a result. Warner Brothers Discovery, which owns HBO, did not respond to a request for comment, and Reddit also did not respond, according to TechCrunch.
Until recently, ClickFix attacks were a rarity, capitalizing on people searching the web for quick tech fixes. They have since evolved into a massive international effort to hack into people's computers, according to TechCrunch. While it is typical for developers to run one-line snippets of code in their computer's terminal, it is less common for regular users to use Command Prompt or PowerShell in Windows or Terminal in macOS. Security researcher Kevin Beaumont said companies that run fleets of Windows computers can block access to these features across the entire domain to prevent them from being exploited, according to the report.
As noted by Ars Technica, a tool for Mac users called BlockBlock can also defend against attacks that try to trick Apple users into hacking themselves, according to TechCrunch.