Security researchers at Push Security have detailed a malvertising campaign that hijacks Google search ads and Microsoft's own Bing redirect infrastructure to serve fake Claude installers to macOS users. The technique, dubbed "Adception" by the researchers, was discovered after the team detected a malicious sponsored result targeting people who searched for "claude mac" on Google.

What makes the campaign unusual is not the payload but the route it takes to reach victims. Instead of sending clicks to an attacker-controlled domain, the sponsored result displayed Bing's legitimate bing.com domain — a destination few users, and few automated ad-review systems, would consider suspicious. For anyone tracking how AI tooling is being abused in the wild, our AI industry coverage has followed a string of similar schemes that trade on the popularity of AI assistants.

How the 'Adception' Redirect Chain Works

According to Push Security's report, a victim who clicked the malicious Google ad first passed through Google's standard advertising redirect before landing on Bing's bing.com/ck/a click-tracking endpoint. That endpoint exists to log clicks on Bing's own search results, but the attackers figured out how to make it forward browsers to a destination of their choosing.

From there, the chain continued through a legitimate but compromised WordPress website belonging to a South American retailer, which finally redirected the visitor to claude-desk-code[.]com — a fake Claude download page built to trick macOS users into running malicious commands.

The researchers believe the routing through Bing's trusted domain is deliberate. By making the ad's final visible destination a Microsoft property, the campaign appears designed to evade advertising security checks, while the compromised WordPress site acts as an interchangeable middleman that can be swapped out if it gets reported and taken offline.

Two Layers of Cloaking

The campaign also uses multiple layers of cloaking to prevent security scanners and curious visitors from ever reaching the payload:

  • The compromised WordPress site checks that visitors arrived with a Bing referrer and specific browser headers before it redirects them anywhere.
  • The fake Claude site runs JavaScript that verifies the visitor came from Google or Bing.
  • Anyone who tries to open the malicious URL directly is bounced to a 404 error page, which makes automated analysis of the attack significantly harder.

Only a visitor who follows the full ad-to-redirect-to-compromise path ever sees the fake installer page.

The Clipboard Swap at the Final Step

The most deceptive element of the campaign sits at the very end of the funnel. The fake download page is a convincing imitation of Anthropic's official Claude installation instructions, and it even displays the company's genuine install command: curl -fsSL https://claude.ai/install.sh | bash.

But when the visitor clicks the copy button, the page silently swaps a malicious command onto the clipboard in place of the real one. The substituted command first prints a message claiming to download Claude from Anthropic's official website. In the background, it decodes a Base64-encoded URL pointing to lake-90[.]com, uses curl to quietly download a .dat file from the attacker's server, and pipes the file's contents directly into macOS's Z shell (zsh) for execution.

A user who follows the instructions carefully — even one who reads the command on screen and compares it against Anthropic's real documentation — sees nothing wrong. The deception happens only in the clipboard, at the moment between clicking copy and pasting into Terminal.

Why Trusted Domains Change the Malvertising Playbook

Typical malvertising campaigns are reasonably easy to spot: the ad points at a lookalike domain, and the browser's address bar gives the game away. Adception inverts that model. The visible destination is bing.com, the intermediate hop is a genuine small-business website, and the final payload is gated behind referrer checks that defeat manual inspection.

Push Security's researchers note that Bing's click-tracking redirects use JavaScript to send visitors onward, which is what allows traffic to be laundered in a way that appears to originate from Bing itself. Because the click-tracking endpoint is core infrastructure, Microsoft cannot simply blocklist it — it has to detect and kill the specific abuse pattern inside its own redirect chain.

The episode is also a reminder of how valuable AI branding has become to criminals. Fake installers for popular AI tools — Claude, ChatGPT, and similar assistants — are an increasingly common lure precisely because millions of people search for download instructions every month and a meaningful share of them are first-time users who do not yet know what a legitimate installer page looks like.

What Users and Teams Can Do

The practical defenses are unglamorous but effective. Install Claude and other developer tools only by navigating directly to the vendor's official website rather than clicking sponsored results. Prefer package managers such as Homebrew, where packages are reviewed and the download source is fixed. And treat any instruction to paste a terminal command from the web with suspicion: paste it into a text editor first and read what actually landed there, because the Adception campaign shows the command you see is no longer guaranteed to be the command you paste.

Organizations can go further by blocking sponsored results for software-related queries at the DNS or proxy layer and by monitoring for outbound connections to unknown domains immediately after install instructions are run on a machine.

Push Security's report does not say how long the campaign ran before it was discovered or how many users ultimately executed the malicious command. Google and Microsoft had not publicly responded to the findings at the time of the report's publication. What is clear is that the boundary between legitimate advertising infrastructure and attacker infrastructure is thinner than most users assume — and that the fastest-growing brands in software are now the ones most worth impersonating.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →