✓ AI-Debiased Article
Rewritten from Hacker News — Front Page • • 2 min read
25 Public broadcaster L R No clear lean ✓ verified
Why this rating? · 9 signals

Signals flagged in the original

  • loaded language: 'malicious'
  • loaded language: 'fake Claude installers'
  • loaded language: 'trusted domain'
  • loaded language: 'less suspicious'
  • loaded language: 'convincing imitation'
  • loaded language: 'trick macOS users'
  • framing: The headline foregrounds the abuse of trusted Google Ads and Bing redirects.
  • framing: The article emphasizes the campaign's evasion and cloaking techniques, consistent with a cybersecurity-risk report.

Analyzed by our bias model Full breakdown ↓

Hackers Exploit Google Ads and Bing Redirects for ClickFix Attacks

Hackers are using Bing search-result redirects in Google ads to lead users to fraudulent Claude installers that deliver ClickFix attacks. This method, known as "Adception," employs multiple layers of cloaking to evade security checks and mislead users into executing malicious commands. The final payload of the attack remains unidentified.

Companies
Push Security
People
Mikko Hyppönen

Hackers are exploiting Bing search-result redirects as click URLs in Google search ads to direct users to fraudulent Claude installers that deliver ClickFix attacks. This technique, referred to as "Adception" by security researchers at Push Security, aims to bypass advertising security checks by using Bing's trusted domain as the ad destination, subsequently redirecting victims through a compromised website to a malicious download page.

The campaign was identified after researchers detected a malicious Google ad targeting users searching for "claude mac." Unlike typical malvertising campaigns that lead victims to attacker-controlled domains, the sponsored result displayed the legitimate bing.com domain, making it appear less suspicious. When clicked, the ad first passed through Google's advertising redirect before reaching Bing's bing.com/ck/a click-tracking endpoint, which forwarded the browser to a legitimate but compromised WordPress website belonging to a South American retailer.

This compromised website then redirected visitors to claude-desk-code[.]com, a fake Claude download page designed to deceive macOS users into executing harmful commands. Bing's click-tracking redirects utilize JavaScript to send visitors to their destination, allowing attackers to make the traffic appear to originate from Bing.

The campaign employs two layers of cloaking to prevent unwanted visitors from accessing the payload. The compromised WordPress website checks for a Bing referrer and specific browser headers before redirecting visitors, while the fake Claude website uses JavaScript to confirm that visitors arrived from Google or Bing. Those attempting to access the malicious site directly are redirected to a 404 error page, complicating analysis by automated security scanners.

The final destination is a convincing imitation of a Claude download page that offers a macOS installer using an installation command entered into the Terminal. While the page displays Anthropic's legitimate installation command, clicking the copy button places a malicious command in the clipboard. This substituted command first prints a message claiming to download Claude from Anthropic's official website, but actually decodes a Base64-encoded URL pointing to lake-90[.]com.

It then uses curl to silently download a .dat file from the attacker-controlled server and pipes its contents directly into the macOS Z shell (zsh) for execution. Victims see the legitimate Claude installation URL both on the download page and in the terminal, despite an entirely different script being executed. The final payload delivered by the attack remains unknown, leaving the nature of the malware, if any, being installed unclear. Push Security has identified several domains associated with the same ClickFix toolkit, tracked internally as AcSig, which utilize an identical macOS installation command, payload URL structure, and installer interface.

Annotating as

No note attached

on this article.

Language Analysis

Loaded-language score 25/100
wirepublicmainstream flavoredpartisanadvocacy
Inflammatory language 12/100
Sentiment -10/100

Loaded Language Removed

  • ✕ loaded language: 'malicious'
  • ✕ loaded language: 'fake Claude installers'
  • ✕ loaded language: 'trusted domain'
  • ✕ loaded language: 'less suspicious'
  • ✕ loaded language: 'convincing imitation'
  • ✕ loaded language: 'trick macOS users'
  • ✕ framing: The headline foregrounds the abuse of trusted Google Ads and Bing redirects.
  • ✕ framing: The article emphasizes the campaign's evasion and cloaking techniques, consistent with a cybersecurity-risk report.
  • ✕ vague attribution: security researchers, attackers

Original vs. Neutral

Original Headline

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

Neutral Headline

Hackers Exploit Google Ads and Bing Redirects for ClickFix Attacks