Claude ClickFix attacks abuse Google Ads and Bing redirects

Claude ClickFix attacks abuse Google Ads and Bing redirects

A malvertising campaign is using Google search ads that point to legitimate Bing redirect links to send Mac users to fake Claude installers carrying ClickFix attacks, according to Push Security.

The researchers call the technique "Adception." It appears built to slip past ad security checks by giving Bing's trusted domain as the ad destination. Victims are then routed through a hacked website before reaching the malicious download page.

An ad that showed bing.com

Push Security found the campaign after spotting a malicious Google ad shown to users searching for "claude mac."

Most malvertising campaigns send victims straight to domains the attackers control. This sponsored result instead displayed bing.com as its domain, which made it look far less suspicious to anyone scanning the search results.

Push traced the click path. The ad first went through Google's own advertising redirect and then reached Bing's click-tracking endpoint at bing.com/ck/a. From there, the browser was forwarded to a legitimate WordPress website run by a South American retailer that had been compromised. That site in turn sent the visitor to claude-desk-code[.]com, a fake Claude download page aimed at macOS users.

Bing's click-tracking redirects rely on JavaScript to move visitors to their destination. This lets attackers point users at malicious sites while the traffic seems to come from Bing.

Two layers of cloaking

The campaign also tries hard to hide its payload from anyone who is not a genuine victim.

The hacked WordPress site only redirects visitors if it sees a Bing referrer and certain browser headers. The fake Claude page then runs its own JavaScript check to confirm the visitor arrived from Google or Bing.

Anyone who opens the malicious site directly lands on a 404 error page. This makes it harder for automated security scanners to reach and analyze the attack.

A copy button that swaps the command

The final page is a convincing copy of a Claude download page. It offers a macOS installer that works by pasting a command into the Terminal.

On screen, the page shows Anthropic's real installation command, curl -fsSL https://claude.ai/install.sh | bash. But clicking the copy button puts a different, malicious command on the clipboard.

When run, the substituted command first prints a message saying it is downloading Claude from Anthropic's official website. In the background, it decodes a Base64-encoded URL that points to lake-90[.]com. It then uses curl to quietly fetch a .dat file from the attacker's server and pipes the contents directly into zsh, the default macOS shell, for execution.

The result is that victims see the genuine Claude installation URL both on the web page and in their terminal, while a completely different script runs.

Push Security has not identified the final payload, so it is not yet clear what malware, if any, ends up on the machine.

The company says it found several other domains linked to the same ClickFix toolkit, which it tracks internally as AcSig. They share the same macOS installation command, payload URL structure and installer interface.

Our Take

This campaign shows how attackers keep stacking trusted services on top of each other. Each hop in the chain, from Google Ads to Bing to a real retailer's website, adds a layer of legitimacy that both users and automated checks tend to accept. Ad review that looks only at the displayed domain seems poorly suited to catch this.

The lure itself fits a pattern we have seen repeatedly. Attackers have already used fake ChatGPT and Gemini sites to target users, and ClickFix keeps turning up in new forms, including the recent Lunex Stealer campaign. Targeting people who search for AI coding tools on Mac suggests a focus on developers, whose machines often hold valuable credentials.

The practical lesson is simple. Install tools from the vendor's own site rather than search ads, and check what is actually in the clipboard before pasting a command into Terminal. It is worth watching whether Google and Microsoft change how ad destinations and click-tracking redirects are validated, and whether researchers manage to identify the final payload behind AcSig.