Fake Claude Ads Use Bing Redirects to Deliver ClickFix Malware to macOS Users
Hackers are abusing legitimate Bing search-result redirects in Google ads to send users to a fake Claude installer that launches a ClickFix attack.
Security researchers at Push Security have dubbed the technique “Adception.” The campaign appears designed to bypass advertising security checks by using trusted Bing domains as ad destinations before redirecting victims through a compromised website to a malicious download page.
The attack also uses multiple layers of cloaking to prevent security scanners and people who visit the malicious URL directly from viewing the payload.
Researchers discovered the campaign after finding malicious Google ads targeting users searching for “claude mac.”
Source: Push Security
Attackers hide behind Bing’s trusted click-tracking domain
Unlike typical malvertising campaigns that redirect victims to domains controlled directly by attackers, these sponsored results displayed the legitimate bing.com domain, making the ads appear less suspicious.
According to Push Security, clicking the ad first sent users through Google’s ad redirect before reaching Bing’s bing.com/ck/a click-tracking endpoint. Bing then redirected the browser to a legitimate but compromised WordPress website operated by a South American retailer.
The compromised website redirected visitors to claude-desk-code[.]com, a fake Claude download page designed to trick macOS users into running malicious commands.
Bing’s click-tracking redirect uses JavaScript to send visitors to their destination. This allows attackers to redirect users to malicious websites while making the traffic appear to originate from Bing.
Multiple cloaking layers block security analysis
The campaign uses two layers of cloaking to prevent unwanted visitors from reaching the payload.
Compromised WordPress websites check for Bing referrers and certain browser headers before redirecting visitors. The fake Claude website also uses JavaScript to verify whether the visitor arrived from Google or Bing.
Visitors who attempt to open the malicious website directly are redirected to a 404 error page, making it more difficult for automated security scanners to analyze the attack.
Fake Claude installer hides malicious macOS commands

Source: Push Security
The final destination mimics a Claude download page and offers macOS installation instructions that require users to enter commands in Terminal.
Although the page displays the official installation command for Anthropic, curl -fsSL | bash, clicking the copy button places a malicious command on the clipboard instead.
The replacement command first displays a message claiming to download Claude from Anthropic’s official website. In reality, it decodes a Base64-encoded URL pointing to lake-90[.]com.
The command then uses curl to silently download a .dat file from an attacker-controlled server and pipes its contents directly to the macOS Z shell, zsh.
As a result, victims see a legitimate Claude installation URL both on the download page and on their device, even though an entirely different script is executed.
The final payload delivered by the attack remains unknown, so it is unclear what malware will ultimately be installed.
Push Security says it identified multiple domains associated with the same ClickFix toolkit, which it tracks internally as AcSig. The domains use the same macOS installation command, payload URL structure, and installer interface.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



