Adception Attack Uses Bing Redirects in Google Ads to Spread Fake Claude Installer
Push Security found a Google ad for 'claude mac' that abused Bing's click-tracking endpoint to redirect users to a fake Claude download page for macOS.
Security researchers at Push Security have uncovered a malvertising campaign that uses legitimate Bing search-result redirects as click URLs in Google search ads to deliver fake Claude installers. The technique has been dubbed "Adception," according to bleepingcomputer.com.
The campaign was detected after researchers found a malicious Google ad targeting the search term "claude mac." The sponsored ad displayed the bing.com domain as its destination and passed through Google's advertising redirect to Bing's bing.com/ck/a click-tracking endpoint. From there, users were forwarded to a compromised WordPress site belonging to a South American retailer.
That compromised site then redirected visitors to claude-desk-code[.]com, a fake Claude download page for macOS. The page displays Anthropic's legitimate install command, but the copy button places a malicious command in the clipboard. The malicious command downloads a .dat file from lake-90[.]com and pipes it into macOS zsh for execution. The final payload of the attack is currently unknown.
Push Security tracks the ClickFix toolkit used in this campaign as AcSig and has identified several associated domains. Visitors who access the malicious site directly are redirected to a 404 error page, a common tactic to evade automated analysis.
Quick answers
What is the Adception malvertising campaign?
It is a technique that uses Google search ads with legitimate Bing redirect URLs to send users to fake Claude installers, as reported by Push Security.
How does the fake Claude installer work?
The fake page shows Anthropic's legitimate install command, but the copy button places a malicious command in the clipboard. That command downloads a .dat file from lake-90[.]com and pipes it into macOS zsh for execution.
What is the final payload of the attack?
The final payload is unknown, according to Push Security.