Hackers Exploit Bing Redirects in Google Ads to Push Fake Claude Installers
Tech

Hackers Exploit Bing Redirects in Google Ads to Push Fake Claude Installers

TechNews Editorial
TechNews EditorialOct 10, 2026 · 2 min read
Share

Why it matters

This campaign demonstrates how threat actors combine trusted ad platforms, search redirects, and clipboard manipulation to bypass security controls and trick users into executing unauthorized scripts.

The facts

  • Hackers are abusing legitimate Bing search redirects in Google ads to target users searching for Claude on macOS.
  • The attack uses cloaking techniques and a clipboard swap to trick users into copying and running malicious terminal commands.
  • Push Security tracks the associated ClickFix toolkit as AcSig, though the final payload remains unknown.

Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads. The campaign directs users to fake Claude installers that deliver ClickFix attacks. Security researchers at Push Security dubbed this technique Adception. The strategy appears designed to evade advertising security checks. It uses Bing's trusted domain as the ad destination before routing victims through a compromised website.

Ads abused trusted domains

The campaign was discovered after researchers detected a malicious Google ad targeting users searching for claude mac. Sponsored results typically direct victims to attacker-controlled domains. In this case, the sponsored result displayed the legitimate bing.com domain. This made the advertisement appear much less suspicious to users.

When clicked, the ad passed through Google's advertising redirect. It then reached Bing's bing.com/ck/a click-tracking endpoint. That endpoint forwarded the browser to a legitimate but compromised WordPress website. The compromised site belonged to a South American retailer. That site then redirected the visitor to claude-desk-code.com. This was a fake Claude download page designed to trick macOS users into executing malicious commands.

Bing's click-tracking redirects use JavaScript to send visitors to their destination. This allows attackers to redirect users to malicious websites. At the same time, it makes the traffic appear to originate from Bing.

A compromised retail website checks incoming browser requests and redirects a qualifying visitor to a counterfeit software download page.
Illustration: AI & Tech News

Cloaking hides malicious sites

The campaign uses two layers of cloaking to prevent unwanted visitors from reaching the payload. The compromised WordPress website checks for a Bing referrer and specific browser headers. The fake Claude website uses JavaScript to verify that visitors arrived from Google or Bing.

Visitors who try to access the malicious site directly are redirected to a 404 error page. This makes it harder for automated security scanners to analyze the attack.

Read nextAnthropic Introduces Dynamic Workflows for Claude Managed Agents

Clipboard swaps hide execution

The final destination is a convincing imitation of a Claude download page. It offers a macOS installer using an installation command entered into the Terminal. The page displays Anthropic's legitimate installation command. However, clicking the copy button places a malicious command in the clipboard.

The substituted command first prints a message claiming to download Claude from Anthropic's official website. It actually decodes a Base64-encoded URL pointing to lake-90.com. It then uses curl to silently download a .dat file from the attacker-controlled server. It pipes its contents directly into the macOS Z shell for execution.

Victims see the legitimate Claude installation URL both on the download page and in the terminal. An entirely different script is executed in the background.

The final payload delivered by the attack remains unknown. It is unclear what malware, if any, is being installed. Push Security identified several domains associated with the same ClickFix toolkit. Push tracks this toolkit internally as AcSig. These domains use an identical macOS installation command, payload URL structure, and installer interface.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Keep reading