Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads. The campaign directs users to fake Claude installers that deliver ClickFix attacks. Security researchers at Push Security dubbed this technique Adception. The strategy appears designed to evade advertising security checks. It uses Bing's trusted domain as the ad destination before routing victims through a compromised website.
Ads abused trusted domains
The campaign was discovered after researchers detected a malicious Google ad targeting users searching for claude mac. Sponsored results typically direct victims to attacker-controlled domains. In this case, the sponsored result displayed the legitimate bing.com domain. This made the advertisement appear much less suspicious to users.
When clicked, the ad passed through Google's advertising redirect. It then reached Bing's bing.com/ck/a click-tracking endpoint. That endpoint forwarded the browser to a legitimate but compromised WordPress website. The compromised site belonged to a South American retailer. That site then redirected the visitor to claude-desk-code.com. This was a fake Claude download page designed to trick macOS users into executing malicious commands.
Bing's click-tracking redirects use JavaScript to send visitors to their destination. This allows attackers to redirect users to malicious websites. At the same time, it makes the traffic appear to originate from Bing.

Cloaking hides malicious sites
The campaign uses two layers of cloaking to prevent unwanted visitors from reaching the payload. The compromised WordPress website checks for a Bing referrer and specific browser headers. The fake Claude website uses JavaScript to verify that visitors arrived from Google or Bing.
Visitors who try to access the malicious site directly are redirected to a 404 error page. This makes it harder for automated security scanners to analyze the attack.
Read nextAnthropic Introduces Dynamic Workflows for Claude Managed AgentsClipboard swaps hide execution
The final destination is a convincing imitation of a Claude download page. It offers a macOS installer using an installation command entered into the Terminal. The page displays Anthropic's legitimate installation command. However, clicking the copy button places a malicious command in the clipboard.
The substituted command first prints a message claiming to download Claude from Anthropic's official website. It actually decodes a Base64-encoded URL pointing to lake-90.com. It then uses curl to silently download a .dat file from the attacker-controlled server. It pipes its contents directly into the macOS Z shell for execution.
Victims see the legitimate Claude installation URL both on the download page and in the terminal. An entirely different script is executed in the background.
The final payload delivered by the attack remains unknown. It is unclear what malware, if any, is being installed. Push Security identified several domains associated with the same ClickFix toolkit. Push tracks this toolkit internally as AcSig. These domains use an identical macOS installation command, payload URL structure, and installer interface.



