Google Ads and Bing redirects lure Mac users into fake Claude ClickFix attack
Push Security found a malvertising campaign, dubbed Adception, that abuses Bing's click-tracking domain to send macOS users to a fake Claude page that swaps the real install command for a malicious one.
At a glance
- A malicious Google ad for 'claude mac' displayed bing.com and redirected through Bing's click-tracking endpoint, according to BleepingComputer.
- Victims landed on claude-desk-code[.]com after passing through a compromised WordPress site.
- The page shows Anthropic's real install command but copies a different one that downloads and runs a script via zsh.
- Push Security tracks the toolkit as AcSig; the final payload remains unknown.
A malvertising campaign is abusing Google Ads and Microsoft Bing's click-tracking redirects to send Mac users searching for Anthropic's Claude to a fake download page that runs a hidden command, BleepingComputer reported on October 9. Researchers at Push Security, who named the campaign "Adception," discovered it after detecting a malicious Google ad shown for the search term "claude mac."
What happened
According to BleepingComputer, the sponsored result displayed bing.com as its destination, making it look more trustworthy than a typical malicious ad. Clicking it sent the browser through Google's ad redirect and then Bing's bing.com/ck/a click-tracking endpoint, which forwarded the user to a compromised WordPress site belonging to a South American retailer. That site in turn redirected visitors to claude-desk-code[.]com, a fake Claude download page aimed at macOS users.
Technical details
The chain relies on cloaking to evade automated scanning, the report said. The compromised WordPress site only redirects visitors that arrive with a Bing referrer and specific browser headers, while the fake Claude site uses JavaScript to confirm the visitor came from Google or Bing. Direct visits are served a 404 error page.
The page then uses the ClickFix social engineering technique. It displays Anthropic's genuine terminal install command, but the copy button places a different command on the clipboard. That command prints a message claiming to download Claude from Anthropic while decoding a Base64-encoded address pointing to lake-90[.]com, silently downloading a .dat file and piping it directly into zsh for execution. As a result, victims see the legitimate address on the page and in the terminal output while a different script runs.
Push Security tracks the toolkit as "AcSig" and has identified several other domains using the same macOS install command, payload URL structure and installer interface, BleepingComputer said. The final payload is not known, and the report did not include victim counts or the campaign's duration.
Who is affected
The campaign targets macOS users looking for the Claude desktop app or command-line tools through search engines. Developers who routinely copy installation commands into a terminal are especially exposed, because the lure mimics a familiar workflow.
What to do
Users should download software only by typing the vendor's official address directly rather than clicking sponsored search results, and should never paste commands copied from a web page into a terminal without checking what was actually copied. Organizations can block the known domains, monitor macOS endpoints for curl output piped into a shell, and report malicious ads to the advertising platforms.
Sources
- Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks — BleepingComputer
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



