Attackers have bought Google search ads that display bing.com as their destination, then bounced victims through a hacked website to a counterfeit Claude installer for macOS. The trick, which London-based Push Security has named “Adception”, is designed to show every automated checkpoint a trusted address while saving the malicious page for real people.
What happened
On 9 October 2026, browser security firm Push Security published an analysis of an attack it caught inside a customer environment. The victim had searched Google for “claude mac”, the obvious query for anyone wanting Anthropic’s AI assistant on an Apple machine. Sitting at the top of the results was a sponsored listing. Its displayed domain was not a lookalike of anthropic.com or claude.ai. It was bing.com.
Clicking that ad started a four-hop journey. Google’s own ad-click redirect handed the browser to Bing’s click-tracking endpoint, which in turn sent it to a genuine, search-indexed “about us” page on a South American homeopathy retailer’s WordPress site that had been compromised. From there, victims landed on claude-desk-code[.]com, a polished imitation of Claude’s download page. BleepingComputer reported the research the same day, and Windows Report followed on 10 October.
Push, whose research was led by Luke Jennings, its vice president of R&D, links the lure domains to a ClickFix toolkit it tracks internally as AcSig. It identified several sibling domains sharing the same install pop-up code and payload URL structure. Neither Push nor BleepingComputer has identified the final payload, so it is unclear what, if anything, any Mac that ran the command received.
The technical picture
The fake page follows a pattern Push has previously called InstallFix. The novelty is how the chain launders trust at each stage.
Every organic link on a Bing results page passes through a click-tracking redirect that records which result was chosen. That redirect forwards the browser using a short piece of JavaScript rather than a standard HTTP redirect, so the next site in the chain sees a bing.com referrer. The attacker took a legitimate Bing result pointing at the page they had compromised and used it as the landing address in a Google ad. To Google’s ad review, the landing address looked like nothing more than a rival search engine, and the ad was approved. Push says it could find no earlier public reporting of a Bing result being used this way inside a search ad.
Two layers of cloaking then decide who sees what. The compromised retailer’s server only forwards visitors carrying a Bing referrer and particular browser headers. The fake Claude page runs its own JavaScript check and sends anyone not arriving from Google or Bing to a 404 error page. Scanners and analysts visiting directly see nothing of interest.
The lure finishes with a social engineering sleight of hand. The page shows Anthropic’s real one-line Terminal install instruction, but the copy button silently swaps in something else. Once pasted into Terminal, that substitute prints a reassuring message naming the genuine claude.ai install script, while in the background it decodes an obfuscated address, pulls a script from an attacker-controlled host and passes it straight to the shell. Anyone who reads the page and then glances at Terminal sees the legitimate Claude address twice.

Why it matters for UK organisations
Developers, data teams and increasingly non-technical staff across the UK are installing AI coding assistants on their own initiative, often on MacBooks. That is exactly the population this campaign targets: people comfortable enough with Terminal to paste an install command, and in a hurry to get a new tool working. On a corporate laptop with access to source code, cloud consoles and single sign-on sessions, one paste can give away a great deal.
Push’s wider telemetry makes the point starkly. The firm says four in every five ClickFix-style attacks it detects, including the InstallFix and shared-chatbot-page variants, reach victims through search engines. Malvertising is the main road in for this family of attacks.
The technique also undermines a lot of conventional advice. “Check the domain before you click” fails when the ad genuinely shows bing.com. URL reputation filters fail when every early hop is a well-regarded domain. Indicator blocklists struggle too: Push notes that the lure domains are cheap and quickly replaced, whereas the reputable hops at the front of the chain tend to stay the same.
Expert view
Redirect abuse is old news. In my experience, open redirects on trusted domains are among the first things we look for when building a phishing pretext on a red team engagement, because they get past mail gateways and make the link look respectable. What is new here is the stacking: one search engine’s result used as the destination of another search engine’s advert, with server-side and client-side gating layered on top. It is a low-cost step, and low-cost steps that work tend to spread quickly through criminal toolkits.
The macOS focus deserves attention too. Many organisations still treat Macs as the lower-risk part of the estate, with lighter endpoint controls and more local administrator rights. ClickFix works by getting the user to run the code themselves, which sidesteps Gatekeeper prompts and download warnings because no file is ever double-clicked. When we test, the Terminal-paste route is consistently one of the quieter ways to get execution on a well-maintained Mac.
“Install from the official site” only helps if staff actually reach it. Clicking the top search result is an ingrained habit, and attackers are paying to sit exactly there.
What to do now
- Give staff a known-good route to AI tools. Publish approved installers or package-managed deployments for Claude and similar assistants through your device management platform, so nobody needs to search for them. This maps to the Cyber Essentials secure configuration and user access control requirements.
- Brief users specifically on paste-to-run lures. The message is simple: never paste a Terminal or PowerShell command copied from a web page or a pop-up unless IT has given it to you, and treat any sponsored search result as an advert, not a recommendation.
- Tighten macOS endpoints. Remove standing local administrator rights where possible, make sure endpoint detection is deployed and tuned on Macs, and alert on shell processes that fetch and immediately execute remote content. This supports the Cyber Essentials malware protection control.
- Hunt for the known indicators, but do not rely on them. Check DNS and proxy logs for claude-desk-code[.]com, lake-90[.]com and the other AcSig domains Push published, then focus detection on behaviour rather than addresses.
- Consider browser-level controls. Ad blocking on managed browsers and tools that watch clipboard writes and full redirect chains can break this class of attack earlier than network filtering.
- Treat any hit as an identity incident. If a device ran the command, assume browser sessions, tokens and stored credentials are exposed: isolate the machine, revoke sessions and rotate secrets.
Bottom line
Adception does not exploit a software flaw. It exploits the assumption that a familiar domain means a safe link, and that an install command on a convincing page is the one that ends up on your clipboard. With AI tools spreading fast through UK workforces, organisations should hand staff a trusted install path before attackers hand them a fake one.
Sources
- Push Security: Adception: malvertising another search engine’s search results to redirect to a malicious page
- BleepingComputer: Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
- Windows Report: Hackers use Google Ads and Bing to spread fake Claude installers
- SiliconANGLE: Push Security nabs $15M to secure companies’ cloud applications