Hackers are abusing legitimate Bing search-result redirects placed as click URLs in Google search ads to lure users to fake Claude installers that deliver ClickFix attacks. Security researchers at Push Security have dubbed the technique "Adception." It appears designed to evade advertising security checks by using Bing's trusted domain as the ad destination before redirecting victims through a compromised website to a malicious download page.
The campaign was discovered after researchers detected a malicious Google ad targeting users searching for "claude mac." Unlike typical malvertising, the sponsored result displayed the legitimate bing.com domain, making it look less suspicious. When clicked, the ad passed through Google's redirect and Bing's click-tracking endpoint, which forwarded the browser to a compromised WordPress website belonging to a South American retailer. That site then sent visitors to claude-desk-code[.]com, a fake Claude download page built to trick macOS users into running malicious commands.
The attack uses layered cloaking to hide its payload. The compromised WordPress site checks for a Bing referrer and specific browser headers, while the fake Claude page uses JavaScript to confirm visitors arrived from Google or Bing. Direct visits are sent to a 404 error page, which makes automated scanners harder to use.
The page displays Anthropic's legitimate installation command, but the copy button places a malicious command on the clipboard. It decodes a Base64-encoded URL pointing to lake-90[.]com, downloads a .dat file, and pipes it directly into zsh for execution. The final payload remains unknown. Push Security has linked several other domains using the same ClickFix toolkit, which it tracks as Ac Sig.
Source: Hacker News · Summarized by HeadlinesBriefing