Security researchers at Push Security have identified a sophisticated malvertising campaign dubbed 'Adception' that weaponizes the trust users place in major search engines. By abusing legitimate Bing search-result redirects as click URLs within Google Ads, attackers are successfully directing users to fake Claude installers. The primary objective is to execute ClickFix attacks, a technique that relies on social engineering rather than complex exploit chains, specifically targeting macOS users searching for the AI assistant.

The 'Adception' Mechanism

The campaign’s innovation lies in its destination domain. Unlike typical malicious ads that point to attacker-controlled domains, these sponsored results display the legitimate bing.com domain. This visual cue significantly lowers user suspicion during the initial click. When a victim clicks the ad, the traffic passes through Google’s advertising redirect and lands on Bing’s bing.com/ck/a click-tracking endpoint. This endpoint, which uses JavaScript to forward visitors, then redirects the browser to a compromised WordPress website belonging to a South American retailer, effectively laundering the malicious traffic through trusted infrastructure.

Cloaking and Payload Delivery

The attack employs a dual-layer cloaking strategy to evade automated security scanners. The compromised WordPress site checks for a Bing referrer and specific browser headers before redirecting, while the final malicious domain, claude-desk-code[.]com, uses JavaScript to verify that visitors arrived from Google or Bing. Any direct access by scanners results in a 404 error page. Once the victim reaches the fake Claude download page, they are presented with what appears to be Anthropic’s official installation command: curl -fsSL https://claude.ai/install.sh | bash. However, the copy button on this page substitutes the visible text with a malicious command in the user’s clipboard.

The Terminal Trap

The substituted command prints a message claiming to download Claude from Anthropic’s official website, but it actually decodes a Base64-encoded URL pointing to an attacker-controlled server, lake-90[.]com. It then uses curl to silently download a .dat file and pipes its contents directly into the macOS Z shell (zsh) for execution. This means victims see the legitimate Claude installation URL both on the webpage and in their terminal history, even though an entirely different, unverified script is being executed. Push Security tracks this toolkit internally as AcSig, noting that the final malware payload remains unknown but the infrastructure is consistent across multiple domains.

Key Takeaways

  • Attackers are using Bing’s trusted domain in Google Ads to bypass user suspicion and ad network checks.
  • The 'Adception' campaign uses a compromised WordPress site as a middleman redirect to hide the true payload origin.
  • ClickFix attacks rely on clipboard substitution, tricking users into executing malicious code while displaying legitimate installation commands.
  • Security scanners are blocked from analyzing the payload via JavaScript cloaking that returns 404 errors for non-referral traffic.

The Bottom Line

This campaign proves that brand trust in AI tools is now a primary attack surface; users must verify command execution sources, not just displayed URLs.