ClickFix attacks infecting PCs and Macs are going viral
Cybercriminals are scaling ClickFix attacks by using fake CAPTCHA overlay windows and compromised social media accounts to infect Windows and macOS devices. These attacks trick users into executing information-stealing malware under the guise of resolving technical errors. Recent campaigns include the use of the official HBO Max Reddit account to distribute malicious ads. The scheme targets both PCs and Macs, leveraging social engineering to convince users to manually trigger the infection process on their own systems.
Listen to Live Briefing
Real-time synthesized voice briefing · Live Feeds Desk
- ✓ ClickFix attacks infect both Windows and macOS devices with information-stealing malware.
- ✓ The attacks use social engineering tactics, including pop-ups and overlays, to trick users into hacking their own computers.
What changed
Attackers are now utilizing hijacked official Reddit accounts and weaponized CAPTCHA overlays to distribute the malware.
Live updates
-
ClickFix attacks expand via fake CAPTCHAs and hijacked social accounts
Cybercriminals are scaling ClickFix attacks by using fake CAPTCHA overlay windows and compromised social media accounts to infect Windows and macOS devices. These attacks trick users into executing information-stealing malware under the guise of resolving technical errors. Recent campaigns include the use of the official HBO Max Reddit account to distribute malicious ads. The scheme targets both PCs and Macs, leveraging social engineering to convince users to manually trigger the infection process on their own systems.
Why it matters
These attacks build on previous campaigns that used fake AI chat interfaces and installers. The malware specifically targets sensitive user data and cryptocurrency wallets. The shift toward CAPTCHA prompts indicates a diversification of social engineering tactics.
What is confirmed
- ClickFix attacks infect both Windows and macOS devices with information-stealing malware.
- The attacks use social engineering tactics, including pop-ups and overlays, to trick users into hacking their own computers.
Still unconfirmed
- Hackers compromised the official HBO Max Reddit account to push malicious ClickFix ads.
- Cybercriminals have weaponized CAPTCHA overlay windows to launch these attacks.
What to watch next
- Identification of the specific malware strains used in the CAPTCHA and Reddit campaigns
- Reports of successful removals or patches for the MacSync stealer
- Confirmation of other hijacked corporate social media accounts used for distribution
confidence 80%Sources used for this update (4)
- arstechnica.com — Dan Goodin
- hothardware.com — ClickFix Malware Is Going Viral, Infecting PCs And Macs With CAPTCHA Prompts
- www.bleepingcomputer.com — Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
- www.techspot.com — Fake CAPTCHAs are tricking people into hacking their own computers, and it's working
-
ClickFix campaigns target PC and Mac users via AI lures
ClickFix attacks are spreading rapidly by using fake AI chat interfaces and installers to infect Windows and macOS devices. Hackers distribute password-stealing malware through deceptive Claude and ChatGPT installers and shared AI conversations. On macOS, the MacSync stealer specifically targets cryptocurrency wallets and user credentials. These campaigns leverage the popularity of generative AI tools to trick users into executing malicious code under the guise of fixing technical errors or installing legitimate software.
Why it matters
The rise of generative AI has created new social engineering vectors for malware delivery. By mimicking trusted AI brands, attackers bypass traditional user skepticism. This shift demonstrates a move toward highly targeted, platform-specific stealers.
What is confirmed
- ClickFix attacks infect both PC and Mac systems.
- Attackers use fake ChatGPT and Claude installers to deploy malware.
Still unconfirmed
- The MacSync macOS stealer targets cryptocurrency wallets and credentials via ClickFix lures.
- Shared AI chats are being used to spread ClickFix malware.
What to watch next
- Identification of the specific threat actors behind the MacSync stealer.
- Release of official security patches or detection signatures from Apple and Microsoft.
confidence 80%Sources used for this update (4)
- Ars Technica — ClickFix attacks infecting PCs and Macs are going viral
- CyberSecurityNews — Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
- B2B Cyber Security — ClickFix: Shared AI chats spread malware
- cyberpress.org — MacSync macOS Stealer Exploits ClickFix Lures to Steal Credentials and Cryptocurrency Wallets
Community Sentiment: How do you assess this situation?
Voice your perspective · Real-time aggregated sentiment from the Live Feeds community