
Hackers have decided that the best way to distribute fake software is through legitimate platforms. They’re utilizing Bing search redirects to lure users into downloading phony Claude installers that deliver ClickFix attacks. Apparently, it’s a new trend to hide malware in plain sight.
Called “Adception” by the geniuses at Push Security, this scheme involves redirecting users through trusted domains to dodge security checks. Users searching for “claude mac” get routed through a compromised site, which ultimately serves up a malicious download.
This isn’t your run-of-the-mill malvertising that typically takes users straight to shady websites. No, these ads display Bing’s domain to trick users into thinking they’re safe. After clicking, users first hit Google’s advertising redirect, then Bing’s click-tracking endpoint before landing on a compromised WordPress site belonging to a retailer in South America. A real global flair to this digital deceit.
And just to add some extra layers of cloak-and-dagger drama, the attackers are using advanced cloaking techniques. A compromised site checks for a Bing referrer and specific browser headers before redirecting. If you try to access the malicious link directly, it just shows you a lovely 404 error page. Nice work if you can get it.
The Fake Installer: A Masterclass in Deception
The final destination of this wild ride is an impressively convincing Claude download page that attempts to fool macOS users into running malicious commands. It displays the legitimate installation command but then substitutes it with a sneaky little trick. Clicking the copy button doesn't copy the real command; instead, it grabs a malicious one. A real “gotcha” moment designed to catch the unsuspecting off guard.
While the page claims to download software from Claude’s official site, it instead pulls a file from an attacker-controlled server and executes it via the macOS terminal. So users think they’re installing a useful tool, but in reality, they’re signing up for malware. The specifics of what that malware does remain a mystery, which only adds to the thrill of the hunt.
Push Security has tracked several domains linked to the same ClickFix toolkit, known internally as AcSig. It’s all very systematic, with identical installation commands and payload structures being deployed across the board.
In short, a clever yet deeply frustrating fusion of technology and trickery, proving once again that where there’s a will, there’s a way—and hackers are nothing if not resourceful.
