SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Fake Claude installer ads on Google borrow Bing's click tracker to display a trusted domain
Attackers route Google ads through Bing's click-tracking redirect to show bing.com and send Mac users to a fake Claude installer, Push Security found. The setup appears built to pass ad vetting, so the domain an ad displays no longer says where a click lands.
The Watch · Security desk
What happened
- Push Security found the campaign through a malicious Google ad shown to people searching for "claude mac".
- A click passes Google's ad redirect and Bing's bing.com/ck/a tracking endpoint, then a compromised WordPress site belonging to a South American retailer.
- The fake download page shows Anthropic's real curl install command, but its copy button puts a different command on the clipboard.
- That substitute prints a message about downloading Claude from Anthropic while decoding a Base64-hidden address at lake-90[.]com.
Why it matters
- exposure Users who vet a sponsored result by its displayed domain get no warning here: the ad showed a Microsoft domain that neither hosted the lure nor served the script.
- constraint Scanners and analysts who load the lure URLs directly land on a 404, so blocklisting depends on replaying the full ad, Bing and referrer chain.
- decision Mac fleets that let staff install AI tools from search results now have to decide whether to require the vendor's site, reached by typing its address, or a managed software catalog.
Once past the click, the victim has to do one thing: run the copied command in Terminal. No software flaw is involved [17]. The command uses curl to pull a .dat file from the attacker's server and pipes it straight into zsh. The shell executes whatever that server returns [12]. On the page and in the terminal, the victim sees the legitimate claude.ai installation address while a different script runs [13]. Push has not identified the final payload, so it is unclear what malware, if any, gets installed [14].
The bing.com label on the ad is real. The ad's click URL is a genuine Bing search-result redirect [1]. Bing's tracker sends visitors onward with JavaScript, so the next site receives traffic that appears to come from Bing [7]. Typical malvertising points its ads at a domain the attacker controls [4]. According to Push, which calls the technique Adception, using Bing's trusted domain as the ad destination appears designed to get past advertising security checks [2].
The chain also filters who gets through. The retailer's WordPress site forwards only visitors carrying a Bing referrer and specific browser headers [8]. The fake download page, claude-desk-code[.]com, then runs JavaScript to check that the visitor arrived from Google or Bing [6][8].
The clipboard swap is the ClickFix part of the attack. The Bing hop is the delivery layer Push named. Push tracks the kit behind the page as AcSig and has tied several domains to it, all using the same macOS install command, payload URL structure and installer interface [15]. I'd treat that as a sustained operation running a reusable kit, with the "claude mac" ad as the front end Push happened to catch [18].
What to watch
- Whether Google or Microsoft changes how ad click URLs that resolve to bing.com/ck/a are reviewed or forwarded.
- Identification of the script served from lake-90[.]com, which would settle what the campaign actually installs.
- AcSig domains turning up behind ads for other AI tools or search terms beyond "claude mac".
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks.
- [2]
Push Security dubbed the technique "Adception"; it appears designed to evade advertising security checks by using Bing's trusted domain as the ad destination before redirecting victims through a compromised website.
- [3]
The campaign was discovered after Push Security researchers detected a malicious Google ad targeting users searching for "claude mac."
- [4]
Unlike typical malvertising campaigns that direct victims to attacker-controlled domains, the sponsored result displayed the legitimate bing.com domain.
- [5]
When clicked, the ad passed through Google's advertising redirect, then Bing's bing.com/ck/a click-tracking endpoint, which forwarded the browser to a legitimate but compromised WordPress website belonging to a South American retailer.
- [6]
The compromised website redirected visitors to claude-desk-code[.]com, a fake Claude download page designed to trick macOS users into executing malicious commands.
- [7]
Bing's click-tracking redirects use JavaScript to send visitors to their destination, allowing attackers to redirect users to malicious websites while making the traffic appear to originate from Bing.
- [8]
The compromised WordPress site checks for a Bing referrer and specific browser headers before redirecting visitors, while the fake Claude website uses JavaScript to verify that visitors arrived from Google or Bing.
- [9]
Visitors who try to access the malicious site directly are redirected to a 404 error page, making it harder for automated security scanners to analyze the attack.
- [10]
The fake page displays Anthropic's legitimate installation command, curl -fsSL https://claude.ai/install.sh | bash, but clicking the copy button places a malicious command in the clipboard.
- [11]
The substituted command first prints a message claiming to download Claude from Anthropic's official website, but decodes a Base64-encoded URL pointing to lake-90[.]com.
- [12]
The substituted command uses curl to silently download a .dat file from the attacker-controlled server and pipes its contents directly into the macOS Z shell (zsh) for execution.
- [13]
Victims see the legitimate Claude installation URL both on the download page and in the terminal, even though an entirely different script is being executed.
- [14]
The final payload delivered by the attack remains unknown, so it is unclear what malware, if any, is being installed.
- [15]
Push Security identified several domains associated with the same ClickFix toolkit, which it tracks internally as AcSig, that use an identical macOS installation command, payload URL structure, and installer interface.
- [16]
The domain displayed on the ad (bing.com) belonged to neither the host of the lure page (claude-desk-code[.]com) nor the host serving the script (lake-90[.]com).
- [17]
The attack exploits no software vulnerability; it depends on the victim running the copied command in Terminal.
- [18]
Several domains sharing one kit, combined with a delivery layer built to evade ad vetting, indicates a sustained operation with a reusable kit, with the "claude mac" ad as one front end.
Sources
1 independent publisher whose own reporting we read for this story.
- bleepingcomputer.comHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.