Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

Hackers are using a clever technique to evade advertising security checks and direct unsuspecting users to malicious download pages. By abusing legitimate Bing search-result redirects in Google Ads, attackers are able to push Claude ClickFix attacks, which ultimately deliver unknown payloads to victims’ devices.

The method, dubbed “Adception” by researchers at Push Security, involves using Bing’s trusted domain as the ad destination before redirecting users through a compromised website to the malicious download page. This multi-layered approach allows attackers to fly under the radar of security scanners and visitors who access the malicious URLs directly. The compromised website checks for a Bing referrer and specific browser headers, while the fake Claude website verifies that visitors arrived from Google or Bing using JavaScript.

The attack begins when a user searches for “claude mac” on Google and clicks on a sponsored ad displaying the legitimate bing.com domain. This redirect passes through Google’s advertising system before reaching Bing’s click-tracking endpoint, which forwards the browser to a compromised WordPress website belonging to a South American retailer. The website then redirects users to claudedesk-code[.]com, a fake Claude download page designed to trick macOS users into executing malicious commands.

The fake Claude installer appears legitimate at first glance, displaying Anthropic’s installation command and offering a convincing imitation of the official download page. However, clicking the copy button places a malicious command in the clipboard that decodes a Base64-encoded URL pointing to lake-90[.]com. The final payload delivered by the attack remains unknown, but researchers have identified several domains associated with the same ClickFix toolkit.

This campaign highlights the ongoing threat of AI-powered attacks and the need for defenders to stay one step ahead of attackers. With the increasing use of trusted platforms like Bing and Google Ads, hackers are finding new ways to evade security checks and deliver malicious payloads. As Anthropic’s infostealer malware hijacks Claude sessions to drain usage, it’s clear that attackers will continue to adapt and evolve their tactics.

To stay secure in this landscape, users must be vigilant when clicking on ads or downloading software from unfamiliar sources. It’s essential to verify the authenticity of download pages and installation commands, even if they appear legitimate at first glance. By building a robust security blueprint for AI-powered attacks, defenders can better prepare themselves for the evolving threat landscape and stay ahead of attackers.

In practical terms, users should exercise caution when interacting with sponsored ads or downloading software from unfamiliar sources. Verifying the authenticity of download pages and installation commands is crucial in preventing attacks like this one. By staying informed and adapting to new threats, we can mitigate the impact of AI-powered attacks and keep our devices secure.


Source: Bleeping Computer — 2026-10-09