Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

    October 10, 2026

    Blockchain.com Seeks Approval for US Prediction Markets and Crypto Derivatives

    October 10, 2026

    A quantum prediction from 1931 just came to life

    October 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects
    • Blockchain.com Seeks Approval for US Prediction Markets and Crypto Derivatives
    • A quantum prediction from 1931 just came to life
    • Zionism, racism and the Green party in turmoil | Green party
    • Three men found guilty of murders of Australian surfer brothers and US friend in Mexico | Mexico
    • France promises 3,000 extra teachers in bid to calm student protests
    • Book Publishers Are Quietly Using More AI. Staff Are Revolting
    • Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 10
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 10, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks.

    The technique, dubbed “Adception” by security researchers at Push Security, appears designed to evade advertising security checks by using Bing’s trusted domain as the ad destination, before redirecting victims through a compromised website to the malicious download page.

    The attack also uses multiple layers of cloaking to prevent security scanners and visitors who access the malicious URLs directly from seeing the payload.

    According to a report published by Push Security, the campaign was discovered after researchers detected a malicious Google ad targeting users searching for “claude mac.”

    Google search ad ultimately redirecting to a fake Claude download page
    Google search ad ultimately redirecting to a fake Claude download page
    Source: Push Security

    Unlike typical malvertising campaigns that direct victims to attacker-controlled domains, the sponsored result displayed the legitimate bing.com domain, making the advertisement appear less suspicious.

    When clicked, Push says the ad first passed through Google’s advertising redirect before reaching Bing’s bing.com/ck/a click-tracking endpoint, which forwarded the browser to a legitimate but compromised WordPress website belonging to a South American retailer.

    The compromised website then redirected the visitor to claude-desk-code[.]com, a fake Claude download page designed to trick macOS users into executing malicious commands.

    Bing’s click-tracking redirects use JavaScript to send visitors to their destination, allowing attackers to redirect users to malicious websites while making the traffic appear to originate from Bing.

    The campaign also uses two layers of cloaking to prevent unwanted visitors from reaching the payload.

    The compromised WordPress website checks for a Bing referrer and specific browser headers before redirecting visitors, while the fake Claude website uses JavaScript to verify that visitors arrived from Google or Bing.

    Visitors who try to access the malicious site directly are redirected to a 404 error page, making it harder for automated security scanners to analyze the attack.

    Fake Claude installer hides malicious commands

    The final destination is a convincing imitation of a Claude download page that offers a macOS installer using an installation command entered into the Terminal.

    ClickFix prompt disguised as installation steps for Claude for macOS 
    ClickFix prompt disguised as installation steps for Claude for macOS 
    Source: Push Security

    However, while the page displays Anthropic’s legitimate installation command, curl -fsSL https://claude.ai/install.sh | bash, clicking the copy button places a malicious command in the clipboard.

    The substituted command first prints a message claiming to download Claude from Anthropic’s official website, but actually decodes a Base64-encoded URL pointing to lake-90[.]com.

    It then uses curl to silently download a .dat file from the attacker-controlled server and pipes its contents directly into the macOS Z shell (zsh) for execution.

    This means victims see the legitimate Claude installation URL both on the download page and in the terminal, even though an entirely different script is being executed.

    The final payload delivered by the attack remains unknown, so it unclear what malware, if any, is being installed.

    Push Security says it identified several domains associated with the same ClickFix toolkit, which it tracks internally as AcSig, that use an identical macOS installation command, payload URL structure, and installer interface.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Abuse ads attacks Bing Claude ClickFix Google hackers Push Redirects
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

    Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

    FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack

    Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

    4 ways Amazon’s new Alexa tablets eclipse the Fire line – starting with Google Play

    Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

    October 10, 2026

    Blockchain.com Seeks Approval for US Prediction Markets and Crypto Derivatives

    October 10, 2026

    A quantum prediction from 1931 just came to life

    October 10, 2026

    Zionism, racism and the Green party in turmoil | Green party

    October 10, 2026
    Latest Posts

    Reform donor Arron Banks urged to set out extent of surveillance of journalists | Arron Banks

    August 10, 2026

    The Canadian Secessionists Who Love Trump

    August 10, 2026

    How ‘Harry Potter’ Fans Protected Dobby’s Grave From the Path of a U.K.-Ireland Power Line

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

    October 10, 2026

    Blockchain.com Seeks Approval for US Prediction Markets and Crypto Derivatives

    October 10, 2026

    A quantum prediction from 1931 just came to life

    October 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.