MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-09 · via BleepingComputer

Malicious ads use Bing redirects to deliver fake Claude installers

Image via BleepingComputer
Image via BleepingComputer

Researchers at Push Security found a campaign that placed Google search ads pointing to legitimate Bing redirect URLs before sending victims to a compromised WordPress site. That site then redirected macOS users to a fake Claude download page designed to trigger ClickFix-style malicious commands. The attack used multiple cloaking layers to hide the payload from scanners and direct visitors.

Expanded Detail

Push Security traced a malvertising chain that began with Google ads for “claude mac.” The sponsored link showed bing.com, then moved through Google’s ad redirect and Bing’s click tracker to a hacked WordPress site tied to a South American retailer, before reaching a counterfeit Claude page.

That page mimicked macOS installation steps. Its copy button swapped Anthropic’s real command for one that decoded a hidden address, fetched a .dat file from lake-90[.]com, and ran it in zsh. Referrer and header checks, plus a 404 fallback, hid the scheme from scanners. The final payload remains unidentified.

Context

This campaign may weaken confidence in search advertising and trusted redirect links, since users could be exposed to malicious installers while believing they are visiting legitimate destinations. macOS users seeking AI tools, along with IT and security teams supporting them, could face malware or other harm if the unidentified payload is malicious. Search platforms and advertisers may also need to reassess how redirect chains and cloaking are monitored, as such tricks could make malicious ads harder to detect at scale.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Compromised Maintainer Accounts Used to Spread Malicious GitHub Workflows · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks.” Browse more stories.