Skip to content
The AI-First Web

A Google ad showing bing.com led to a fake Claude installer

Push Security found the ad and its first hops showed trusted names, while cloaking hid the final fake page from scanners

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
A Google ad showing bing.com led to a fake Claude installer
In brief
  • Push Security found a Google ad that displayed bing.com, passed through a compromised retail site, and ended at a fake Claude download page.
  • The ad and the early hops showed trusted names, and cloaking hid the final page from scanners. The fake page also swaps what the Copy button places on the clipboard.
  • Leaders should ask whether defenses watch browser behaviour, not only links, and give staff one approved way to install AI tools.

Someone searches Google for "claude mac". The top result is a sponsored ad. The domain printed under it reads bing.com. Nothing about that looks wrong, and that is the whole design.

Push Security, a browser security vendor, detected this attack in a customer environment. The researchers call the technique "Adception": a search result placed inside a search ad. The lesson here is that trust is being lent, not earned. Attackers borrow a famous name to pass the checks that look at addresses, then decide at the last moment who sees the real page.

What Push found

The ad's listed domain was bing.com. Clicking it sent the browser through a Bing search-result redirect, then through a compromised WordPress site belonging to a South American homeopathy retailer. The visitor finally landed on a convincing fake Claude download page offering a macOS installer.

Push says Google's ad review let through an ad whose destination was just another search engine. The researchers say they found no earlier public report of a Bing result being used as the landing address of a search ad. BleepingComputer, which covered the report, names the fake site as claude-desk-code[.]com and says the ad first passed through Google's own ad redirect.

One limit matters here. A person who reaches the end sees the fake site's own address in the browser bar. The trusted names appear earlier: on the ad, on the Bing hop and on the compromised site's hop. Cloaking, covered below, is what keeps scanners from ever seeing the final page.

4 in 5
ClickFix attacks Push detects that reach victims via search engines
Source: Push Security blog post on Adception (BleepingComputer coverage dated October 9, 2026)

How the chain works

Bing puts a tracking link, bing.com/ck/a, behind every result on its own pages. That lets it log clicks before sending people on. The real destination sits inside the link as encoded text. Bing then forwards the visitor with a short page of JavaScript, not a standard redirect. As a result, the next site sees a bing.com referrer, the record of where the visitor came from.

The attacker took a real Bing result for a page on the compromised site and used that link as the ad's destination. Push reads a timestamp inside the link as October 5, 2026, which it thinks is when Bing generated it.

2
Layers of cloaking guarding the payload
Source: Push Security (October 2026)

Cloaking means showing scanners something harmless. The compromised site checks for a Bing referrer and certain browser headers. The fake Claude site then runs its own JavaScript check. If the visitor did not come from Google or Bing, it sends them to a 404 error page. A security team that pastes the final address into a scanner sees nothing.

The trick inside the install step

On screen, the page lists Anthropic's genuine one-line installer, which fetches a script from claude.ai. The Copy button quietly puts a different command on the clipboard. Push and BleepingComputer both describe the substitute: it prints a message claiming to fetch Claude from Anthropic, then decodes a hidden web address and downloads a file from lake-90[.]com. It passes that file straight to the Mac's zsh shell to run.

In short, the pasted command prints a message naming Anthropic's site while it fetches and runs a different script. BleepingComputer reports that the final payload is unknown, so what the script installs is not established. Push links the domains to a ClickFix toolkit it tracks as AcSig.

Who carries the risk

Most checkpoints a phishing link meets judge a URL. Push lists email gateways, ad platforms, URL filters and users glancing at a domain. In this chain, the ad reviewer and the person clicking saw a name they trust at the early hops. The decision about who gets the malicious page comes last, on a domain that can be replaced within days, according to Push.

The employee who wanted a legitimate AI tool is the obvious target. The retailer is the other party in the chain: its site was compromised and used as a hop in someone else's attack. Push also reports that redirects of this kind are common: it lists Microsoft sign-in links, Google URL wrappers, LinkedIn Smart Links and SendGrid click tracking among those abused.

A fair caveat: Push sells browser security, and this is one campaign. It shows how trusted redirects can be stacked. It does not measure how many such ads exist.

What to ask your team

Ask your security lead whether detection watches what happens in the browser session, such as a page writing a command to the clipboard, or only scores the links people click. Push says the first approach holds up when redirects change, while it calls indicator lists for short-lived campaigns like this of limited value.

Ask IT for one approved route to install AI tools, such as a managed software catalogue, so staff do not search for installers. Ask whether pasting commands into Terminal is allowed on company Macs, and by whom.

Ask your web team whether your own sites could be a hop. A compromised page that ranks in search is useful to an attacker. Patch and monitor it.

A trusted name on the first hop proves little about the last one. Judge the destination, not the doorway.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Push Security.

Share this insight