Cookie Consent by Free Privacy Policy Generator

ClickFix Social Engineering Attacks Target Mac and Windows Users

A new wave of ClickFix attacks has been targeting both macOS and Windows users through compromised social media accounts and malicious advertising. The campaign has been described as a "massive 48-hour malvertising blitz" that included the compromise of the HBO Max Reddit account. ClickFix attacks trick users into copying and running malicious commands by presenting fake error messages or system prompts that instruct users to paste and execute code in their terminal or PowerShell. The attacks bypass traditional technical controls by relying entirely on social engineering to convince users to manually execute malware on their own systems. The technique is effective because it mimics legitimate troubleshooting steps that users may have encountered before, and because it works across different operating systems and security configurations.

Why this matters for UK organisations

ClickFix represents a shift in attacker tactics that UK organisations need to understand and prepare for. These attacks succeed not because of a software vulnerability, but because they manipulate users into bypassing security controls themselves. The technique is effective because it mimics legitimate troubleshooting steps that users may have encountered before, and because it works across different operating systems and security configurations. The compromise of high-profile social media accounts like HBO Max's Reddit presence shows how attackers are using trusted channels to distribute these attacks. Traditional endpoint protection may not detect or block ClickFix attacks because the malicious code is executed voluntarily by the user, making awareness and user education critical defensive layers. For organisations where users have administrative access to their devices or where PowerShell and terminal access is not restricted, the risk is particularly significant.

What to review

For many organisations, this is a reminder to review user awareness training and ensure that staff understand the risks of copying and running commands from untrusted sources. Consider whether your current security awareness programme covers social engineering techniques that bypass technical controls, and whether users would recognise a ClickFix attack if they encountered one. Review whether administrative access and scripting tools like PowerShell are appropriately restricted, and whether endpoint detection and response tools would flag unusual command execution patterns. Consider whether your organisation's culture encourages users to seek help from IT support when they encounter unusual error messages, rather than following instructions from unknown sources. Ensure that security awareness training is practical, relevant and regularly updated to reflect emerging techniques like ClickFix that rely on manipulating user behaviour rather than exploiting technical vulnerabilities.

Source: TechCrunch

News and blog posts
GitLab has disclosed a critical path traversal vulnerability, CVE-2026-85706,...
A new wave of ClickFix attacks has been targeting both macOS and Windows users...
Revolut has confirmed a customer data breach that occurred through fake...
Today's brief focuses on vulnerabilities being actively exploited in widely...