Cyber Attackers Now Hide Behind the Tools Built to Stop Them
Article

Cyber Attackers Now Hide Behind the Tools Built to Stop Them

Two new attack patterns show adversaries weaponizing trusted security infrastructure and the people paid to negotiate with them.

SuryaOctober 10, 20265 min read

Photo: BleepingComputer

The attacks logged this week share one trait: adversaries are no longer breaking the tools built to stop them. They are standing inside them. Legitimate ad redirects, mainstream AI brands, and the cybersecurity firms hired to clean up after a breach are all being turned into attack infrastructure. For US technology companies and consumers, the trust embedded in that infrastructure is now the vulnerability.

Abuse of Trusted Redirects

The first pattern concerns how attackers reach victims, not how they breach them. According to BleepingComputer, hackers are abusing legitimate Bing search-result redirects as the click URLs in Google search ads, sending users to fake Claude installers that deliver ClickFix attacks.

The mechanics matter more than the brands. The ad itself is a Google ad. The click passes through a genuine Bing redirect. The destination impersonates a well-known AI product. Each hop is a piece of mainstream infrastructure that users, browsers, and ad review systems have reason to treat as ordinary. ClickFix then converts that trust into execution, typically by coaxing the user into running a command themselves.

This is a structural problem for the US ad market. Google and Bing sell and broker the paths that carry this traffic, and both are American platforms with enormous reach. The abuse exploits the space between them, where one platform's redirect legitimizes a link that another platform's ad system is supposed to police. Advertisement review has always been a hard problem; this technique makes it a cross-platform one.

The AI Installer as Lure

The choice of a fake Claude installer is not incidental. AI assistants have become default software for US businesses and consumers, and installation is one of the few remaining moments when a user expects to download and run something new.

That expectation is what ClickFix monetizes. Users seeking a tool they already intend to use are guided through steps that end in a malicious command. The brand supplies the intent; the redirects supply the apparent legitimacy.

For US technology companies, the implication is uncomfortable. The AI vendors whose names appear in these campaigns do not control the ad networks or the redirect chains that carry them. They control only their own distribution. When a fake installer is served through infrastructure they have no authority over, brand monitoring and takedowns become the primary defensive tools, and both operate after exposure rather than before it.

The Middlemen Under Indictment

The second pattern concerns who gets arrested. According to KrebsOnSecurity, FBI agents arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group, which Krebs reported had recently relieved the FBI of sensitive data on thousands of agents. BleepingComputer separately reported that Canadian cybersecurity executive Edward Dubrovsky was arrested in Pennsylvania in connection with alleged extortion activity that multiple reports have linked to the FBI's crackdown on ShinyHunters.

A ransomware negotiation firm is, by design, a bridge between victims and criminals. That position is legitimate and often necessary. It is also the position from which alleged extortion can be conducted with unusual cover, because contact with attackers is the job description.

The detail that the group in question reportedly obtained FBI data on thousands of agents raises the stakes beyond ordinary extortion. When a hacking group holds sensitive government material, the firms that negotiate with it sit close to the most consequential decisions in the incident response chain. That proximity is exactly what makes the role worth scrutinizing.

The Negotiator Problem

Cybersecurity firms have sold themselves to US enterprises as the trusted layer between a breach and its consequences. Incident response, negotiation, and recovery are services bought precisely because the buyer cannot verify what the vendor is doing.

If a negotiator can be credibly accused of participating in the extortion rather than resolving it, the trust model behind an entire US service category comes into question. Companies that hire such firms often do so under legal pressure, with regulators, insurers, and boards watching. They rely on the vendor's representations about contacts with attackers, payments, and recovered data. There is little independent visibility into any of it.

The arrests do not establish guilt. They do establish that US law enforcement is willing to treat the negotiation layer as a target rather than a resource. That changes the calculus for every US firm that has ever routed a ransom decision through a third party, and for the insurers and counsel who recommend them.

Why the Two Patterns Are One

Both developments describe the same shift. Defensive trust is being converted into attack capacity.

In the ad campaigns, the trusted asset is infrastructure: a platform redirect and a recognizable product name. In the arrests, the trusted asset is a person and a firm whose business is access. In each case, the attacker does not need to defeat the security model. The attacker needs to occupy a part of it.

For US technology companies, this argues against treating any single layer as inherently clean. A verified ad can carry a hostile redirect. A named security vendor can become the subject of an investigation. Trust has to be re-established at each step rather than inherited from the last one.

For US consumers, the practical exposure is narrower but real. The ClickFix campaigns rely on a user following instructions delivered through what appears to be a normal search and advertising path. The relevant habit is not suspicion of AI tools but suspicion of instructions that arrive alongside them.

What to Watch

The stories point to specific things worth tracking rather than general trends. On the advertising side, whether Google and Bing adjust how redirect URLs are treated in ad review, and whether the fake-installer campaigns migrate to other AI brands, are the observable questions. BleepingComputer's reporting identifies the technique, not its durability.

On the enforcement side, the charges against Dubrovsky and the FBI investigation into ShinyHunters are the items to follow, along with whether other firms in the negotiation and incident response space face similar scrutiny. KrebsOnSecurity's account ties the arrest to a group that reportedly obtained FBI data on thousands of agents, which suggests the investigation is not narrow.

The common thread is that both attack surfaces remain open as long as legitimate infrastructure and legitimate intermediaries are treated as automatically trustworthy. That is the condition to monitor, and it is the one neither story resolves.

More on this beat: Cybersecurity on TechManNews.

#cyber attacks#ClickFix#malvertising#ShinyHunters#ransomware#incident response

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.