Skip to content

Fake Claude installers ride Google ads through Bing redirects

Push Security details 'Adception,' a malvertising chain abusing Google ad clicks and Bing click-tracking redirects to send macOS users to fake Claude installers running a ClickFix command.

Published 3 min read

Attackers are threading malicious Google search ads through Bing's click-tracking redirects to land macOS users on fake Claude installer pages, where a ClickFix lure runs an attacker command. Push Security documented the chain, which it nicknames Adception; the toolkit behind the fake pages it tracks internally as AcSig. BleepingComputer reported the campaign on October 9.

How the redirect chain works

Push found a Google ad targeting searches for "claude mac." A click walked through four hops:

  1. Google's ad-click redirect (google.com/aclk).
  2. Bing's click-tracking endpoint (bing.com/ck/a), which forwards via JavaScript — so the visible ad domain is bing.com, not an attacker host.
  3. The compromised "about us" page of a South American retailer running WordPress.
  4. The fake download page at claude-desk-code[.]com.

Bing's redirect is the trick: routing through it makes the traffic look like it originates from a trusted search engine. Push says the Bing link's timestamp decodes to October 5, 2026, so the ad was live roughly four days before disclosure.

The ClickFix payload

The fake page copies Anthropic's real macOS install instructions and displays the legitimate command, curl -fsSL https://claude.ai/install.sh | bash. The Copy button, however, places a different command on the clipboard — one that prints a reassuring "Downloading Claude" line, then base64-decodes a URL and pipes a remote script into zsh. Push did not identify the final payload.

Both the compromised WordPress site and the fake page cloak: the WordPress host checks for a Bing referrer and specific browser headers before forwarding, and the lure page verifies the visitor came from Google or Bing. Direct visits are sent elsewhere, which frustrates scanners.

Indicators

Indicators, copied verbatim from Push Security's report:

# Fake Claude download pages (AcSig)
Claude-desk-code[.]com
ksmgakajgpsals.pages[.]dev
rapid-craft567[.]com
too.clawddddd[.]com
fine-byte2[.]com
fairpoint29[.]com
turbowave45[.]com
cli-desktop[.]com

# Compromised redirector
homeopatiaalemana[.]com/quienes-somos/

# Payload
lake-90[.]com/curl/inhgup9a/a90fkbqdg8d0mus64oh8dw.dat

# Google ad campaign
gad_campaignid=24303361122

What to do today

  1. Install developer tooling from the vendor's documented source, not from a search ad — type claude.ai directly rather than clicking a sponsored result.
  2. Alert on curl … | zsh/| bash one-liners copied into terminals on managed macOS fleets; the clipboard-swap is the whole attack.
  3. Block the domains above and hunt for connections to lake-90[.]com.
  4. Treat bing.com/ck/a referrers arriving at install pages as suspicious — the redirect is being abused for reputation laundering.

Context

ClickFix keeps migrating onto trusted surfaces and trusted brands: we've covered it impersonating custom GPTs to drop a RAT and riding a Ghost CMS campaign. Adception adds a reputation-laundering layer — the attacker never has to show their own domain in the ad — and AI-tool brand names are now the bait of choice. The copy-button swap means the command a victim reads is not the one they paste; "it shows claude.ai" is no longer reassurance.

Related stories