Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks.
The technique, dubbed "Adception" by security researchers at Push Security, appears designed to evade advertising security checks by using Bing's trusted domain as the ad destination, before redirecting victims through a compromised website to the malicious download page.
The attack also uses multiple layers of cloaking to prevent security scanners and visitors who access the malicious URLs directly from seeing the payload.
According to a report published by Push Security , the campaign was discovered after researchers detected a malicious Google ad targeting users searching for "claude mac."
Unlike typical malvertising campaigns that direct victims to attacker-controlled domains, the sponsored result displayed the legitimate bing.com domain, making the advertisement appear less suspicious.
When clicked, Push says the ad first passed through Google's advertising redirect before reaching Bing's bing.com/ck/a click-tracking endpoint, which forwarded the browser to a legitimate but compromised WordPress website belonging to a South American retailer.
The compromised website then redirected the visitor to claude-desk-code[.]com , a fake Claude download page designed to trick macOS users into executing malicious commands.
Bing's click-tracking redirects use JavaScript to send visitors to their destination, allowing attackers to redirect users to malicious websites while making the traffic appear to originate from Bing.
The campaign also uses two layers of cloaking to prevent unwanted visitors from reaching the payload.
The compromised WordPress website checks for a Bing referrer and specific browser headers before redirecting visitors, while the fake Claude website uses JavaScript to verify that visitors arrived from Google or Bing.
Visitors who try to access the malicious site directly are redirected to a 404 error page, making it harder for automated security scanners to analyze the attack.
Fake Claude installer hides malicious commands
The final destination is a convincing imitation of a Claude download page that offers a macOS installer using an installation command entered into the Terminal.
However, while the page displays Anthropic's legitimate installation command, curl -fsSL https://claude.ai/install.sh | bash , clicking the copy button places a malicious command in the clipboard.
The substituted command first prints a message claiming to download Claude from Anthropic's official website, but actually decodes a Base64-encoded URL pointing to lake-90[.]com .
It then uses curl to silently download a .dat file from the attacker-controlled server and pipes its contents directly into the macOS Z shell ( zsh ) for execution.
This means victims see the legitimate Claude installation URL both on the download page and in the terminal, even though an entirely different script is being executed.
The final payload delivered by the attack remains unknown, so it unclear what malware, if any, is being installed.
Push Security says it identified several domains associated with the same ClickFix toolkit, which it tracks internally as AcSig, that use an identical macOS installation command, payload URL structure, and installer interface.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Related Articles:
Google Gemini could soon get full access to your Mac’s files, apps and the web
Custom ChatGPTs push ClickFix attacks to deploy RAT malware
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
New Infinity Stealer malware grabs macOS data via ClickFix lures
Comments
You may also like:
Ransomware recovery CEO charged over secret ransom payments
FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
Low-cost Android phones ship with residential proxy malware
Move from visibility to action with AITEM, Criminal IP’s next evolution of ASM
New OAuth risk analyst agent: Turn 45 minutes of manual review into 15 seconds.
AWS saw a valid key and let the agent clear a production bucket. See how Token Security ties each agent to its owner and limits it to read-only access.
Free Identity Governance for up to 150 Users: Try Our Community Edition
Is your backup really out of reach? See what the latest attacks reveal.
Learn how to evaluate RMM security with eight practical tests. Find gaps before scaling endpoint management across customer environments.