Malvertising: fake Claude installers ride Bing redirects

Claude's popularity has made it a lure — and today's campaign shows how much trust an ad can borrow. One story, dissected.
Hackers are running a fake Claude download page through Google Ads, and the trick is that the ad's destination looks like a Microsoft domain. Security researchers at Push Security, who dubbed the technique "Adception," found a sponsored Google result targeting people searching for "claude mac" whose click URL was a legitimate Bing search-results redirect — so the ad passes Google's checks pointing at bing.com, then Bing's click-tracking endpoint bounces the visitor through a compromised WordPress site belonging to a South American retailer, and only then to a counterfeit Claude page. Two layers of cloaking sit in between: the WordPress hop checks for a Bing referrer and specific browser headers, and the fake Claude site verifies the visitor arrived from Google or Bing — anyone who opens the URL directly, including most security scanners, gets a 404.
The payload delivery is the part that should worry macOS users most. The fake page shows Anthropic's genuine install command, but its copy button swaps a different command into the clipboard — one that prints a friendly "downloading Claude" message while actually decoding a hidden web address, pulling a data file from an attacker-controlled server, and feeding it straight into the Mac's shell. The victim sees the real Claude URL in their terminal while an entirely different script runs. The final payload is still unknown; Push Security says several domains share the same installer interface, command structure, and payload layout, which it tracks internally as one toolkit.
What makes this more than another malvertising story is the laundering chain: attackers no longer need their own domain to look trustworthy in an ad — they rent credibility from a search engine's redirect instead, and the brand they counterfeit is simply whichever AI tool people are installing this week. It's the same pattern behind the stolen-access trade we covered in September — Hackers are selling stolen Claude and Gemini access at 97% off — where the product being abused is trust in Claude itself.
What to watch: whether Google and Bing close the redirect-as-click-URL hole, and what the recovered payload turns out to be.
Have you seen a "Claude installer" ad that didn't lead where it claimed? Tell us in the comments.




