Hackers hide fake Claude installers behind Bing redirects in Google ads
Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
Push Security researchers uncovered an "Adception" campaign where malicious Google ads point to Bing's trusted click-tracking domain, which then bounces victims through a compromised WordPress site to a fake Claude download page. Two layers of cloaking hide the payload from scanners, and a copy button swaps Anthropic's real install command for a Base64-encoded script that pipes a remote .dat file straight into macOS zsh. The final payload remains unknown.
This means victims see the legitimate Claude installation URL both on the download page and in the terminal, even though an entirely different script is being executed.
- beloch
If you know (or are related to) anyone who is likely to click on scam links like these, do them a favour and install an adblocker on their browser. Upgrade them to a better browser if necessary. Don't just tell them they should do this. Sit down at their computer and do it for them. Ads have become a safety risk and that's not going to change anytime soon.
- jurf
Such a wonderful garden path sentence [1].
- 7373737373
Google appears to either not screen ads at all or willingly allows misleading and lying ads and scams to reach its users. They profit off fraud by either laziness and ignorance or malice, by letting "ads" like "Your PDF reader needs an update" through. And they don't act on them when they are reported.
Every single company putting ads up in public is held to a higher standard.