
A Google ad with a Bing link leads to a fake Claude installer
Security firm Push Security found an ad that tells Mac users to paste a command different from the one on screen. What it installs is still unknown.
A Google ad catches people who search for "claude mac", according to a report from the security firm Push Security dated Oct. 9. The ad shows bing.com as its domain, that of a rival search engine, and the click ends on a page posing as the Claude installer for Mac.
Before it gets there, the click passes through a Bing tracking link and the compromised site of an online store. BleepingComputer describes it as a WordPress shop run by a South American retailer. Push argues that the team reviewing Google's ads approved a destination that was nothing more than another search engine.
The trap is in the copy button. The page displays what looks like Anthropic's install command, but puts a different one on the clipboard. That command decodes a Base64 address, downloads a file with curl and hands it to zsh, the Terminal shell, to run it. Push says the window shows a legitimate Claude address while the script runs.
How it hides
The chain checks where the visitor came from. The compromised site requires a visit from Bing, and the fake page requires one from Google or Bing: anyone arriving directly gets a 404 error. That makes it harder for an analyst to reproduce the attack.
Push calls the method "Adception". It ties it to a ClickFix kit, a type of attack in which the user pastes a command believed to be legitimate, and tracks it as AcSig. Other domains reuse the same installer and the same command, according to the report, which lists them. The company says it detected the case in a customer's environment and that its customers do not need to do anything.
What is not known
Neither Push nor BleepingComputer has identified the final program: BleepingComputer calls it unknown. They also do not say whether Google pulled the ad or whether Microsoft closed the Bing redirect route, and there is no country-level data, so it is not known whether there were cases in Mexico.
The two sources are effectively one: BleepingComputer reports Push's findings and is not an independent check. What the command installs, and when the ad disappears, remain to be confirmed.



