Security researchers at Push Security have uncovered a campaign in which attackers used legitimate Bing search-result redirects as the click destinations for Google search ads, funneling users toward fake Claude installers that deliver ClickFix attacks. Push Security calls the technique "Adception," and says it appears built to slip past advertising security checks by pointing ads at Bing's trusted domain before redirecting victims through a compromised website to a malicious download page. The campaign was found after researchers spotted a malicious Google ad served to users searching for "claude mac."

According to a Push Security report, clicking the ad first passed through Google's advertising redirect and then reached Bing's bing.com/ck/a click-tracking endpoint. That endpoint forwarded the browser to a legitimate but compromised WordPress site belonging to a South American retailer, which in turn redirected the visitor to claude-desk-code[.]com, a fake Claude download page aimed at tricking macOS users into running malicious commands. Bing's click-tracking redirects rely on JavaScript to send visitors onward, letting attackers route traffic to malicious sites while making it appear to come from Bing.

The operation also uses two layers of cloaking to keep unwanted visitors away from the payload. The compromised WordPress site checks for a Bing referrer and specific browser headers before it redirects anyone, while the fake Claude page uses JavaScript to confirm visitors arrived from Google or Bing. Anyone trying to reach the malicious site directly is sent to a 404 error page, a step that makes automated security scanning harder.

The final page closely imitates a Claude download page and offers a macOS installer built around a command entered into the Terminal. It displays Anthropic's legitimate installation command, curl -fsSL https://claude.ai/install.sh | bash, but clicking the copy button places a different command on the clipboard. That substituted command prints a message claiming to download Claude from Anthropic's official website while actually decoding a Base64-encoded URL pointing to lake-90[.]com. It then uses curl to quietly download a .dat file from the attacker-controlled server and pipes its contents straight into the macOS Z shell, or zsh, for execution.

The result is that victims see the legitimate Claude installation URL both on the download page and in the terminal even though an entirely different script runs. The final payload delivered by the attack remains unknown, so it is unclear what malware, if any, is installed. Push Security said it identified several domains tied to the same ClickFix toolkit, which it tracks internally as AcSig, that share an identical macOS installation command, payload URL structure and installer interface.

More cybersecurity news from TechManNews.