Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
The technique, named "Adception" by the team at Push Security who discovered it, was detailed in BleepingComputer's report published October 9, 2026.
By Dillip Chowdary • Oct 10, 2026 • Source: BleepingComputer
Security researchers have uncovered a malvertising campaign that hijacks legitimate Bing search-redirect infrastructure to serve fake Claude AI installers laced with ClickFix payloads, bypassing Google's ad-policy checks in the process. The technique, named "Adception" by the team at Push Security who discovered it, was detailed in BleepingComputer's report published October 9, 2026.
This piece covers exactly how the multi-hop redirect chain works, why bing.com's trusted domain was chosen as cover, what the fake Claude page does to a visitor's clipboard, and what remains unknown about the final payload — relevant to anyone using macOS who has ever searched for AI tools through Google.
Hackers abuse Google Ads: what actually changed
Push Security researchers spotted the campaign after detecting a malicious Google ad targeting users who searched for "claude mac." What made the ad unusual was its destination domain: the sponsored result displayed the legitimate bing.com address rather than an attacker-controlled site, which made the advertisement appear far less suspicious than a typical malvertising link. Conventional malvertising campaigns route victims directly to domains the threat actor owns or controls; this one inserted Bing's click-tracking infrastructure as a trusted intermediate stop.
The domain shown in the ad — bing.com — passes visual inspection and, Push Security argues, is likely designed to pass advertising platform security checks as well. Google's ad-review systems evaluate destination URLs, so using a recognizable, high-reputation domain as the listed click target reduces the probability of the ad being flagged or rejected before it reaches users. Push Security tracks the underlying toolkit internally as AcSig and identified multiple domains associated with it that share an identical macOS installation command, payload URL structure, and installer interface.
Hackers abuse Google Ads: how it works

When a user clicked the ad, the browser passed first through Google's own advertising redirect, then landed at Bing's bing.com/ck/a click-tracking endpoint. Bing uses JavaScript at that endpoint to forward visitors onward, and in this campaign it forwarded traffic to a legitimate but compromised WordPress website belonging to a South American retailer. That retailer's site then redirected the visitor to claude-desk-code[.]com, a convincing imitation of an Anthropic download page aimed at macOS users.
Two cloaking layers protected the payload from automated analysis. The compromised WordPress site checked for a Bing referrer and specific browser headers before executing the redirect, and the fake Claude site ran JavaScript to confirm visitors arrived from Google or Bing. Anyone attempting to load the malicious URL directly — as an automated scanner typically would — was sent to a 404 error page instead, effectively hiding the attack from security tooling that inspects ad destinations by fetching them without the expected referrer chain.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
Hackers abuse Google Ads: why it matters now
The Adception technique matters because it exploits the trust relationship between two major advertising and search ecosystems simultaneously. By routing through bing.com/ck/a, attackers leveraged Microsoft's own click-tracking service as an unwitting redirect layer, making the traffic appear to originate from Bing even though it ultimately led to a malicious domain. That same redirect mechanism is a routine part of Bing's search-result infrastructure, meaning defenders cannot simply block bing.com click-tracking without affecting legitimate Bing traffic.
The ClickFix payload delivery method compounds the problem. Rather than dropping a malicious file directly, the fake Claude page displayed Anthropic's real installation command — curl -fsSL https://claude.ai/install.sh | bash — in visible text on the page, giving the impression of legitimacy. When the user clicked the copy button, the clipboard silently received a different command entirely: one that decoded a Base64-encoded URL pointing to lake-90[.]com, fetched a .dat file from that attacker-controlled server, and piped the contents directly into the macOS Z shell for execution.
Hackers abuse Google Ads: who is affected
The campaign specifically targeted macOS users searching for Claude on Google. The fake installer page was engineered for macOS, the malicious clipboard command invoked zsh, and the lure was built around the Claude brand — making the primary risk population people on Apple hardware who were actively looking to install Anthropic's AI assistant. The audience of someone searching "claude mac" is likely technically comfortable enough to open Terminal and run an installation command, which is precisely the behavior the ClickFix technique exploits.
Push Security's researchers note that the final payload delivered by the attack remains unknown, so it is unclear what malware, if any, was ultimately installed on victims' machines. The campaign does fit a pattern: related ClickFix activity has previously been observed delivering remote-access trojans through fake ChatGPT installers, and a separate wave of Infinity Stealer malware used ClickFix lures to grab macOS data. The AcSig toolkit Push Security identified spans several domains, suggesting the operators have built reusable infrastructure for this class of attack rather than running a one-off campaign.
Hackers abuse Google Ads: what to watch
The attack chain Push Security documented involves at least five distinct hops — Google ad click, Google redirect, Bing click-tracking, compromised WordPress retailer, fake Claude site — each of which is designed to look legitimate in isolation. That layering makes attribution harder and interception at any single point insufficient. Defenders watching for ClickFix campaigns will need to account for the possibility that the URL displayed in a Google ad may be two or three redirects removed from the actual destination domain.
Push Security says it identified several domains associated with the AcSig toolkit beyond claude-desk-code[.]com and lake-90[.]com, all sharing the same macOS command structure and installer interface. That consistency suggests the operators are running a scalable template rather than manually crafting each lure. Anthropic separately warned earlier in 2026 that infostealer malware was hijacking Claude sessions to drain usage credits, signaling that the Claude brand has become a consistent target for threat actors looking to exploit interest in AI tooling.
Developer Action Items
- ☐ Verify the claim on the official Anthropic / Claude / Google page (or BleepingComputer), not from this recap alone.
- ☐ Name the surface that moved — API, policy, model, hardware, or commercial terms — before you Slack the thread.
- ☐ Assign one owner a day to read the primary material and decide: this-sprint, this-quarter, or noise.
- ☐ Do not change production on day-one coverage. Watch the vendor changelog and one independent write-up first.
Hackers abuse Google Ads FAQ
What is the Adception technique used in this attack?
Adception is a method named by Push Security in which attackers use a legitimate Bing click-tracking URL as the destination of a Google ad, hiding the malicious redirect chain behind a trusted domain and bypassing ad-platform security checks.
What does the fake Claude installer actually do?
The page displays Anthropic's real installation command in text, but clicking the copy button replaces the clipboard with a different command that fetches a Base64-decoded URL from lake-90[.]com, downloads a .dat file, and pipes it directly into the macOS Z shell.
What is the final malware payload?
Push Security states the final payload remains unknown; it is unclear what malware, if any, is installed after the .dat file is executed.
Who is most at risk from this campaign?
macOS users who searched for "claude mac" on Google and clicked the sponsored result are the primary target, since the fake installer and clipboard command are both built specifically for macOS and invoke zsh.
How did cloaking prevent security scanners from detecting the attack?
The compromised WordPress intermediary checked for a Bing referrer and specific browser headers, and the fake Claude site verified that visitors arrived from Google or Bing; direct access attempts were sent to a 404 page.
Sources
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
Anthropic is cutting off its internal evaluations from the internet
Read →
ARTEX AI, Claude agents used in cyberattacks on South Korean banks
Read →
Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
Read →
Liquid AI's d1 is available on AI Gateway
Read →
Today's Tech Pulse briefing
Full briefing →
Advertisement