Hackers Use Google Ads and Bing to Spread Fake Claude Installers


claude malware
Image credit: Anthropic

Hackers are exploiting legitimate Bing search-result redirects in malicious Google ads to distribute fake Claude installers targeting macOS users.

Security researchers at Push Security uncovered the campaign, dubbed “Adception,” after identifying a sponsored Google search result targeting users searching for “claude mac.”

The attackers use Bing’s trusted domain to conceal malicious destinations and redirect victims to a fake Claude download page that tricks them into executing dangerous Terminal commands.

How hackers exploit Bing redirects in Google ads

The attack begins when users click a malicious Google-sponsored result that appears to offer the Claude application for macOS.

Instead of taking users directly to the malicious website, the ad redirects them through Bing’s legitimate search infrastructure before sending them to a compromised website.

That website then forwards visitors to a fake Claude installer hosted at claude-desk-code[.]com.

By routing traffic through Bing, the attackers make the advertising link appear more trustworthy while hiding the final malicious destination.

Two layers of cloaking hide the malicious installer

The campaign uses two layers of cloaking to prevent security scanners and automated analysis tools from detecting the malicious content.

The compromised website checks whether visitors arrived through Bing and whether their browsers use the expected settings.

The fake Claude website performs another check to determine whether visitors came through Google or Bing.

Users who attempt to visit the malicious website directly encounter a 404 error instead of the fake installer.

These checks help attackers restrict access to users following the intended advertising path while concealing the malicious content from security researchers.

Fake Claude installer secretly copies malicious commands

The fake download page uses ClickFix techniques to convince macOS users to execute malicious commands.

Although the page displays Anthropic’s legitimate Claude installation command, its copy button secretly places a different command on the clipboard.

The malicious command points to the attacker-controlled domain lake-90[.]com.

When victims paste and execute the command in Terminal, it uses curl to download a .dat file and pipes its contents directly into the macOS Z shell (zsh).

The command also displays a misleading message claiming that Claude is downloading from Anthropic’s official website.

This approach allows attackers to execute remote scripts while making victims believe they are following legitimate installation instructions.

Push Security has not determined the final payload delivered through the malicious installation script.

However, researchers identified several related domains that use the same ClickFix toolkit, which they internally track as AcSig.

These websites share identical macOS installation commands, similar payload URL structures, and matching fake installer interfaces.

The findings suggest that attackers are using the same infrastructure and techniques across multiple malicious websites.

How macOS users can avoid the attack

Users should download Claude only through Anthropic’s official website and carefully inspect installation commands before executing them.

In particular, users should verify commands after pasting them into Terminal because a website’s copy button might insert different instructions from those displayed on the page.

They should also avoid unfamiliar commands that download and immediately execute remote scripts.

The campaign demonstrates that legitimate domains appearing in sponsored search results do not necessarily guarantee a safe download destination.

Separately, Anthropic recently committed $100 million to its Claude Frontier Academy, launched an open-source vulnerability scanner powered by Claude, and introduced Claude Haiku 5.5 with 75% lower costs.

Via BleepingComputer

More about the topics: Claude, Cybersecurity

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages