The Spectrum Dispatch News

technology

Hackers abuse Google Ads and Bing redirects to deliver fake Claude installers

Researchers discovered a malvertising campaign using Bing's trusted domain to bypass ad security checks and distribute ClickFix malware targeting macOS users.

Hackers abuse Google Ads and Bing redirects to deliver fake Claude installers

Security researchers at Push Security have uncovered a sophisticated malvertising campaign that leverages legitimate Bing search-result redirects within Google ads to distribute fake Claude installers containing ClickFix attacks.

Hackers abuse Google Ads and Bing redirects to deliver fake Claude installers

The technique, termed “Adception,” exploits Bing’s trusted domain reputation to evade advertising security checks. Rather than directing users to attacker-controlled domains, the malicious Google ads display the legitimate bing.com URL, making the sponsored result appear trustworthy to both users and security systems.

When clicked, the ad passes through Google’s advertising redirect to reach Bing’s bing.com/ck/a click-tracking endpoint, which then forwards the browser to a compromised WordPress website belonging to a South American retailer. From there, victims are redirected to claude-desk-code[.]com, a fake Claude download page designed to deceive macOS users.

According to Push Security’s report, the campaign was discovered after researchers detected a malicious Google ad targeting searches for “claude mac.” Bing’s click-tracking redirects use JavaScript to forward visitors to destinations while making the traffic appear to originate from Bing itself.

The attack employs multiple layers of cloaking to prevent security analysis. The compromised WordPress site checks for Bing referrer headers and specific browser properties before redirecting, while the fake Claude website verifies that visitors arrived from Google or Bing using JavaScript. Direct access attempts result in 404 error pages, hindering automated security scanner analysis.

The final payload presents a convincing imitation of Anthropic’s Claude download interface, displaying the legitimate installation command: curl -fsSL https://claude.ai/install.sh | bash. However, clicking the copy button places a malicious command in the clipboard instead.

The substituted command displays a message claiming to download Claude from Anthropic’s official website but actually decodes a Base64-encoded URL pointing to lake-90[.]com. It then uses curl to silently download a .dat file from the attacker-controlled server and pipes its contents directly into macOS’s Z shell for execution. Victims see the legitimate Claude installation URL both on the page and in the terminal, despite different code executing.

Push Security identified several domains associated with the same ClickFix toolkit, tracked internally as AcSig, using identical macOS installation commands, payload URL structures, and installer interfaces. The final payload delivered remains unknown, leaving unclear what malware, if any, is being installed on compromised systems.

Key facts

  • Hackers used Bing’s trusted domain in Google ads to bypass security checks and direct users to fake Claude installers
  • The malware is part of the ClickFix toolkit and targets macOS users searching for Claude
  • The attack uses multiple redirect layers through Google Ads, Bing’s click-tracking endpoint, and a compromised WordPress site
  • The fake installer displays legitimate Claude installation commands but executes malicious code from attacker-controlled servers
  • Multiple layers of cloaking prevent security scanners and direct visitors from accessing the malicious payload

Sources

← All posts