Trusence Every claim has a source
Last updated 10 October 2026 Search Türkçe
← All stories
Security

Google Ads and Bing redirects used to hide fake Claude installer on macOS

The campaign uses trusted ad and redirect paths to reach macOS users searching for Claude, making the fake installer harder to spot before the malicious command runs.

Security researchers say attackers are abusing Google Ads and Bing’s redirect infrastructure to hide a fake Claude installer that leads macOS users into a ClickFix-style attack. Push Security found the campaign after spotting a malicious Google ad for people searching for "claude mac," where the visible destination was bing.com rather than an obvious attacker domain. The ad chains through Google’s redirect, Bing’s bing.com/ck/a tracking URL, and a compromised WordPress site before landing on claude-desk-code[.]com, while cloaking rules block direct visitors and many scanners. On the fake download page, the visible install command is legitimate, but the copy button drops a different command that fetches a Base64-obfuscated URL and runs a .dat file through zsh. Push Security says it has seen multiple domains using the same AcSig ClickFix toolkit pattern, but the final payload has not been identified.

Why it matters

For macOS users looking for Claude, the trusted-looking ad path lowers the chance of spotting the trap before they reach the fake download page. The attack also shows how ad and redirect infrastructure can be used to mask the real destination while delivering a command that fetches and runs a .dat file. Push Security’s finding that several domains use the same toolkit pattern suggests the campaign is part of a wider set of related sites, even though the final payload is still unknown.

Sources

  • BleepingComputer