Hackers abuse Google Ads and Bing redirects to push Claude ClickFix attacks
Push Security researchers uncovered an "Adception" campaign where attackers buy Google ads for "claude mac" and route traffic through Bing's trusted click-tracking redirect and a compromised WordPress site to a fake Claude download page. The copy button swaps Anthropic's legitimate install command for a malicious one that downloads a .dat file and pipes it into macOS zsh.
- Ad traffic passes through bing.com/ck/a and a hacked South American retailer site
- Fake page shows Anthropic's real command but copies a malicious one
- Two cloaking layers check Bing referrer and browser headers
- Direct visits to the malicious site get a 404 to evade scanners
Read next
Security