Hackers exploit Google ads; Bing redirects fuel Claude ClickFix attacks
claude google
| Source: HN | Original article
Hackers are exploiting Google Ads and legitimate Bing search-result redirects as click URLs to funnel users toward fraudulent Claude ClickFix attacks.
Hackers have launched a new malvertising operation that blends Google Search ads with Bing’s click‑tracking redirects to distribute a counterfeit Claude AI installer for macOS. Security researchers at Push Security, who have dubbed the scheme “Adception,” say the campaign begins with a sponsored Google ad for the term “claude mac.” Clicking the ad does not lead directly to a landing page; instead, it forwards the user to a legitimate Bing search‑result URL, which in turn routes traffic through a compromised retail website before delivering a fake Claude installer.
The installer is not merely a nuisance. Once executed, it drops the ClickFix payload, a macOS‑focused malware family that runs malicious terminal commands under the guise of legitimate installation instructions. By chaining together two major ad platforms, the attackers sidestep the security checks that each network applies to its own inventory, exploiting the trust placed in Bing’s redirect infrastructure to evade detection.
The technique matters because it highlights a blind spot in the ad‑tech supply chain: cross‑network redirects can be weaponised without triggering the individual platforms’ anti‑malware safeguards. As more advertisers rely on automated bidding and third‑party tracking, the risk of similar “ad‑to‑ad” abuse grows, potentially exposing millions of users to unwanted software and data‑exfiltration tools.
Watch for responses from Google and Microsoft, who are expected to tighten redirect validation and improve real‑time monitoring of sponsored content. Security teams should also consider auditing redirect logs and strengthening vendor‑risk programs to spot anomalous traffic patterns early. Push Security’s findings underscore the need for coordinated defenses across ad ecosystems to keep malicious campaigns like Adception at bay.
Sources
Back to AIPULSEN