Malvertising: fake Claude installers ride Bing redirects

Share
Malvertising: fake Claude installers ride Bing redirects

Claude's popularity has made it a lure — and today's campaign shows how much trust an ad can borrow. One story, dissected.


Hackers are running a fake Claude download page through Google Ads, and the trick is that the ad's destination looks like a Microsoft domain. Security researchers at Push Security, who dubbed the technique "Adception," found a sponsored Google result targeting people searching for "claude mac" whose click URL was a legitimate Bing search-results redirect — so the ad passes Google's checks pointing at bing.com, then Bing's click-tracking endpoint bounces the visitor through a compromised WordPress site belonging to a South American retailer, and only then to a counterfeit Claude page. Two layers of cloaking sit in between: the WordPress hop checks for a Bing referrer and specific browser headers, and the fake Claude site verifies the visitor arrived from Google or Bing — anyone who opens the URL directly, including most security scanners, gets a 404.

The payload delivery is the part that should worry macOS users most. The fake page shows Anthropic's genuine install command, but its copy button swaps a different command into the clipboard — one that prints a friendly "downloading Claude" message while actually decoding a hidden web address, pulling a data file from an attacker-controlled server, and feeding it straight into the Mac's shell. The victim sees the real Claude URL in their terminal while an entirely different script runs. The final payload is still unknown; Push Security says several domains share the same installer interface, command structure, and payload layout, which it tracks internally as one toolkit.

What makes this more than another malvertising story is the laundering chain: attackers no longer need their own domain to look trustworthy in an ad — they rent credibility from a search engine's redirect instead, and the brand they counterfeit is simply whichever AI tool people are installing this week. It's the same pattern behind the stolen-access trade we covered in September — Hackers are selling stolen Claude and Gemini access at 97% off — where the product being abused is trust in Claude itself.

What to watch: whether Google and Bing close the redirect-as-click-URL hole, and what the recovered payload turns out to be.

Have you seen a "Claude installer" ad that didn't lead where it claimed? Tell us in the comments.

Read more

Today in AI — October 10, 2026

Today in AI — October 10, 2026

A day where the boring machinery took center stage: proof checkers, order books, warehouses and the humble text message — plus fresh arguments about who gets to declare any of it safe. Models & Research * Mathematicians get a reliability primer for the Lean Theorem Prover. A guest post by Thomas Hales on Terence Tao's blog walks through what Lean actually guarantees — and devotes itself to the "Summer of Soundness Bugs," the string of kernel bugs found this summer that let false proofs thr

Nadella calls for an AI emergency brake humans control

Nadella calls for an AI emergency brake humans control

Microsoft's CEO spent Saturday redefining what "trusting" a frontier model means — and his answer borrows straight from enterprise security: assume it's already compromised. Satya Nadella is calling for advanced AI systems to be built with containment, independent controls, and an "emergency brake" that lets authorized people pause or shut a model down mid-task. In a post on X, the Microsoft CEO argued that companies deploying frontier AI should not simply take model makers' word for how safe

Nvidia in talks for Reflection AI deal, possibly an acquihire

Nvidia in talks for Reflection AI deal, possibly an acquihire

Two stories today both come down to how the big labs get their hands on talent and technology — one at the billion-dollar scale, one at the filing-receipt scale. Nvidia is in talks to acquire Reflection AI or deepen its existing stake in the open-weights startup, according to the Financial Times — and the shape of the deal may matter as much as the price. The FT reports the talks are early, that an agreement could come in the coming weeks, and that it may still fall apart; Reuters and Bloomber

Vibe-codedTgameTporZ

Vibe-codedTgameTporZ

Classic console games are collapsing into the web at a pace nobody asked for: in the past two weeks, hundreds of AI-decompiled ports of PS2- and PS3-era titles have appeared online, and several of them play like the real thing. Hundreds of AI-decompiled games — Halo: CE, GTA: Vice City, Call of Duty: Black Ops, Skate 3, The Simpsons: Hit and Run — now run in a browser tab, and the ones we've seen reports of don't look like bootleg garbage. Kotaku's Lewis Parker spent time with the ports and re