Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Fake Claude installer ads on Google borrow Bing's click tracker to display a trusted domain

Attackers route Google ads through Bing's click-tracking redirect to show bing.com and send Mac users to a fake Claude installer, Push Security found. The setup appears built to pass ad vetting, so the domain an ad displays no longer says where a click lands.

The Watch · Security desk

How we use AISend a correction

What happened

  • Push Security found the campaign through a malicious Google ad shown to people searching for "claude mac".
  • A click passes Google's ad redirect and Bing's bing.com/ck/a tracking endpoint, then a compromised WordPress site belonging to a South American retailer.
  • The fake download page shows Anthropic's real curl install command, but its copy button puts a different command on the clipboard.
  • That substitute prints a message about downloading Claude from Anthropic while decoding a Base64-hidden address at lake-90[.]com.

Why it matters

  • exposure Users who vet a sponsored result by its displayed domain get no warning here: the ad showed a Microsoft domain that neither hosted the lure nor served the script.
  • constraint Scanners and analysts who load the lure URLs directly land on a 404, so blocklisting depends on replaying the full ad, Bing and referrer chain.
  • decision Mac fleets that let staff install AI tools from search results now have to decide whether to require the vendor's site, reached by typing its address, or a managed software catalog.

Once past the click, the victim has to do one thing: run the copied command in Terminal. No software flaw is involved [17]. The command uses curl to pull a .dat file from the attacker's server and pipes it straight into zsh. The shell executes whatever that server returns [12]. On the page and in the terminal, the victim sees the legitimate claude.ai installation address while a different script runs [13]. Push has not identified the final payload, so it is unclear what malware, if any, gets installed [14].

The bing.com label on the ad is real. The ad's click URL is a genuine Bing search-result redirect [1]. Bing's tracker sends visitors onward with JavaScript, so the next site receives traffic that appears to come from Bing [7]. Typical malvertising points its ads at a domain the attacker controls [4]. According to Push, which calls the technique Adception, using Bing's trusted domain as the ad destination appears designed to get past advertising security checks [2].

The chain also filters who gets through. The retailer's WordPress site forwards only visitors carrying a Bing referrer and specific browser headers [8]. The fake download page, claude-desk-code[.]com, then runs JavaScript to check that the visitor arrived from Google or Bing [6][8].

The clipboard swap is the ClickFix part of the attack. The Bing hop is the delivery layer Push named. Push tracks the kit behind the page as AcSig and has tied several domains to it, all using the same macOS install command, payload URL structure and installer interface [15]. I'd treat that as a sustained operation running a reusable kit, with the "claude mac" ad as the front end Push happened to catch [18].

What to watch

  • Whether Google or Microsoft changes how ad click URLs that resolve to bing.com/ck/a are reviewed or forwarded.
  • Identification of the script served from lake-90[.]com, which would settle what the campaign actually installs.
  • AcSig domains turning up behind ads for other AI tools or search terms beyond "claude mac".

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks.

    ReportedSupportedSource: BleepingComputer, reporting Push Security researchView cited source
  2. [2]

    Push Security dubbed the technique "Adception"; it appears designed to evade advertising security checks by using Bing's trusted domain as the ad destination before redirecting victims through a compromised website.

    ReportedSupportedSource: Push Security, via BleepingComputerView cited source
  3. [3]

    The campaign was discovered after Push Security researchers detected a malicious Google ad targeting users searching for "claude mac."

    ReportedSupportedSource: Push Security report, via BleepingComputerView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · October 9, 2026

    Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories