Claude ClickFix attack uses Google Ads and Bing redirects
Researchers say attackers used legitimate Google ads that land on Bing click-tracking redirects and a compromised WordPress site to deliver fake Claude installers that swap a real install command for a malicious one.
BleepingComputer and Push Security report that attackers ran a campaign using Google search ads that appear to point to bing.com, then send victims through Bing click-tracking redirects and a compromised WordPress site to a fake Claude installer. The fake page shows Anthropic's real install command but replaces the copied text with a different command that downloads and executes a file, a technique Push Security calls "Adception." (BleepingComputer report).
How the Claude ClickFix attack works
According to Push Security and reported by BleepingComputer, the sponsored Google ad routed clicks through Google's ad redirect, then to Bing's click-tracking endpoint at bing.com/ck/a. That endpoint used JavaScript to forward the browser, which let the attackers make the traffic look like it came from Bing. The Bing redirect then sent visitors to a legitimate but compromised WordPress site belonging to a South American retailer, which in turn redirected to a fake download page at claude-desk-code[.]com.
The campaign uses multiple layers of cloaking to avoid detection. The compromised WordPress site checks for a Bing referrer and specific browser headers before issuing the redirect. The fake Claude website uses JavaScript to verify that a visitor arrived from Google or Bing, and anyone who tries to open the URL directly is sent to a 404 page. Push Security found the ad targeting by spotting a Google ad for the search term "claude mac."
On the fake installer page, visitors see the legitimate Anthropic install command, but the copy button puts a different command in the clipboard. That substituted command decodes a Base64 URL, downloads a .dat file from an attacker-controlled server (reported as lake-90[.]com), and pipes the file into the macOS Z shell for execution. The report says Push Security is tracking several domains using the same ClickFix toolkit, which it calls AcSig, and that the final payload delivered by the attack is unknown.
Why this matters for small businesses and public teams
This campaign shows two practical risks: first, attackers can use trusted domains and ad redirects to make malicious links look legitimate to users and some automated checks. Second, a web page that shows a legitimate command while putting a different command into the clipboard can trick even confident users into running a harmful command in Terminal.
Many small organizations host or rely on third-party sites, plugins, and advertising. A compromised WordPress site can become an invisible step in an attack chain, and advertising redirects can hide the true destination. That makes it harder for nontechnical staff to judge whether a result is safe.
What to do now
- If a staff member or user asks about installing Claude or similar software from search results, direct them to the official site rather than an ad. Verify installers on the vendor's official pages.
- Never paste and run a command you did not type yourself. Before running a copied command, check the clipboard contents and the full command in the Terminal. Avoid commands that pipe downloaded content straight into a shell.
- Train staff to treat ads for installers with extra caution and to report suspicious ads to the ad platform (Google) and to your IT or security contact.
- Check any WordPress sites you manage for unauthorized redirects or recently changed content, review administrator accounts, and inspect plugins and themes for unexpected modifications.
- Block or monitor connections to unfamiliar domains seen in suspicious commands, and keep incident contacts ready if you find compromise.
- Scammers often start with your website. See what an attacker can already learn about yours by visiting our security page: Scammers often start with your website.
What we still do not know
The reports make clear how the redirect and clipboard trick work, but they do not identify the final payload. BleepingComputer and Push Security say Push Security tracked multiple domains using the same toolkit, and Push Security named the technique "Adception." Until more analysis is published, defenders should assume the downloaded .dat file could be any malicious script or installer and treat similar incidents as high risk.
If you run search campaigns or host public-facing sites, this case is a reminder to watch for unexpected redirects and to give staff an easy, repeatable checklist for handling installer links. Report suspicious ads and keep users from running commands they did not compose themselves.
Sources
This post was drafted with AI from the reporting linked above and published by Jones Web Designs. For full details, read the original sources.