Fake Claude installer ads abuse Google and Bing redirects to hijack clipboards

Security researchers at Push Security have uncovered a malvertising campaign that impersonates Claude's macOS installer, abusing Google and Bing ad infrastructure to trick users searching for «claude mac» into running a malicious command on their own machines, rather than relying on malware being silently installed.
The technique, known as ClickFix, tricks victims into executing an attacker-chosen command themselves rather than exploiting a software vulnerability. Push Security found this specific campaign, which it has named «Adception,» after detecting a malicious Google ad targeting that exact search term.
How the Redirect Chain Works
The attack's effectiveness comes from a layered redirect chain designed to look legitimate at every step. The sponsored Google ad result displays the legitimate bing.com domain, making it appear less suspicious than a typical sponsored link. Clicking it routes the victim through Google's own ad redirect system, then through Bing's `bing.com/ck/a` click-tracking endpoint — a real Microsoft-owned URL — which forwards the victim to a compromised WordPress site belonging to an unrelated South American retailer. That hijacked site then performs the final redirect to a lookalike domain, `claude-desk-code[.]com`.
Each hop in the chain also checks its visitor before proceeding: the compromised WordPress site verifies the visitor arrived via a Bing referrer with specific headers, and the fake Claude site checks that traffic came from Google or Bing before rendering the malicious page. Anyone who visits the final domain directly — including automated security scanners — receives a generic 404 error instead of the attack page, a cloaking technique that helps the campaign evade detection.
The Trick in the Clipboard
The fake Claude page displays Anthropic's real, legitimate install command — `curl -fsSL https://claude.ai/install.sh | bash` — exactly as it would appear on the genuine site. But the page's copy button doesn't copy that visible text. Instead, it silently places a different command on the victim's clipboard: one that prints a message claiming to download Claude, decodes a Base64-encoded URL pointing to a separate attacker-controlled domain, downloads a `.dat` file via curl, and pipes it directly into zsh for execution. Victims who paste the command into Terminal, as the fake page instructs, see the legitimate-looking URL both on the page and echoed in their terminal output — with no visible sign that a different payload is actually running.
Push Security says the final payload delivered by the `.dat` file is unknown, so the actual malware installed on victims' machines has not been identified. The firm has linked several other domains to the same attack toolkit, which it tracks under the name «AcSig,» based on shared characteristics including identical macOS install command structure, matching payload URL patterns, and a consistent fake-installer interface across the linked domains — indicating this is an established, reusable attack kit rather than a one-off campaign.
Why This Matters Beyond One Fake Download Page
This campaign is notable less for its payload, which remains unconfirmed, than for what it reveals about the state of ad-platform abuse: a chain that passes through both Google's and Microsoft's legitimate ad infrastructure, hijacks an unrelated small business's website as a relay, and impersonates a specific, currently prominent AI company's installer to catch developers specifically searching for that tool. As AI coding tools see rising adoption, searches for their installers have become a viable target for this kind of layered social engineering — and the use of a real company's legitimate install command as camouflage, with only the clipboard contents swapped, is a technique that will likely resurface targeting other AI tools' installers, as reported by BleepingComputer.
Originally reported by BleepingComputer. Read the original article for additional details.
View original source