Cyberattackers have been exploiting a vulnerability in Google’s advertising system, using Bing search-result redirects as click URLs to direct unsuspecting users to fake download pages for the popular AI tool, Claude. The technique, dubbed “Adception” by security researchers at Push Security, is designed to evade security checks and deceive even the most vigilant visitors.
The campaign targets macOS users searching for “claude mac,” displaying a seemingly legitimate Bing search result that appears less suspicious than typical malvertising campaigns. However, when clicked, the ad redirects victims through multiple layers of cloaking, first passing through Google’s advertising redirect before reaching Bing’s click-tracking endpoint. This endpoint then forwards the browser to a compromised WordPress website belonging to a South American retailer, which in turn redirects visitors to a fake Claude download page.
The attackers’ goal is to trick users into executing malicious commands on their macOS devices. The fake Claude installer displays an identical installation command to the legitimate one, making it difficult for even experienced users to detect the deception. However, clicking the copy button places a malicious command in the clipboard, which decodes and downloads a .dat file from an attacker-controlled server, executing it silently in the background.
The compromised WordPress website checks for specific browser headers and referrer information before redirecting visitors, making it challenging for automated security scanners to analyze the attack. Additionally, the fake Claude website uses JavaScript to verify that visitors arrived from Google or Bing, further obscuring the malicious payload.
While the final payload delivered by the attack remains unknown, security researchers have identified several domains associated with the same ClickFix toolkit, which suggests a sophisticated and coordinated effort by cyberattackers. This campaign serves as a stark reminder of the evolving threat landscape, where even trusted AI platforms can be turned into an attack surface.
As we navigate this increasingly complex cybersecurity environment, it’s essential to remain vigilant and educate ourselves on the latest threats. For users, this means being cautious when clicking on search results, especially those that appear suspicious or out of place. By staying informed and adapting our security posture, we can better protect ourselves against these sophisticated attacks.
In light of this campaign, we recommend reviewing your online security settings and taking extra precautions when interacting with unfamiliar websites or download pages. Remember to always verify the authenticity of software installations and be wary of commands that seem too good (or bad) to be true. By staying ahead of the curve, we can reduce the impact of these attacks and maintain our digital safety in an ever-changing threat landscape.
Source: Bleeping Computer — 2026-10-09