Skip to content
NewsIncident

Fake Claude installer ads chain through Google and Bing redirects to hit macOS users

· by Pondero Newsdesk

The short version

Push Security found a malvertising campaign called Adception that routes a Google ad for 'claude mac' through Bing's trusted click-tracking domain before landing on a lookalike site that tricks users into running a malicious terminal command.

Fake Claude installer ads chain through Google and Bing redirects to hit macOS users

A Google search ad for "claude mac" now routes through Bing's own click-tracking domain before dropping victims on a fake Claude download page, a detour researchers say exists purely to dodge ad-network fraud checks.

What

Push Security identified the campaign, which it calls Adception, and traced a single malicious ad through four hops: Google's advertising redirect, then Bing's trusted bing.com/ck/a tracking endpoint, then a compromised WordPress site belonging to an unrelated South American retailer, and finally a lookalike domain, claude-desk-code[.]com, per Push Security's research as reported by BleepingComputer. Routing through Bing's own domain lets the ad pass as a trusted referrer to automated scanners that would otherwise flag a direct jump to a fresh lookalike site. The fake page checks for a Bing referrer and matching browser headers before showing its payload, a cloaking step meant to keep security tools and casual visitors seeing a clean page while the intended target sees the attack. Victims who land on the real payload see what looks like a normal Claude installation command, but the page's copy button swaps in a malicious version that pulls a Base64-encoded script from a second domain, lake-90[.]com, and runs it through macOS Z shell, a social-engineering technique security researchers call ClickFix. BleepingComputer reported the campaign on October 9 and said Push Security found several other domains built on the same toolkit, though the article did not disclose a total ad count or confirm what final payload the script installs.

The attack targets the moment before anyone even opens Claude

Operators who search for AI-tool installers are themselves the attack surface here: nothing about this campaign touches Anthropic's servers or Claude's product. The entry point is a paid search ad, which means the usual advice to check a URL's domain is not enough on its own, since the visible ad and the first redirect both look legitimate until the chain resolves. Anyone installing Claude on macOS (or any AI tool advertised through search) should type the vendor's URL directly rather than clicking a search ad, and should never paste a terminal command copied from a download page without reading what is actually on the clipboard first. IT teams that allow macOS Terminal access without restriction are the most exposed, since the entire attack depends on a user running one pasted shell command.

Sources