Fake Claude Mac installer ads hide behind Bing redirects to run ClickFix commands

Malicious Google ads show bing.com URLs to send Mac users to a fake Claude page pushing a ClickFix Terminal command; final payload unknown.

Fake Claude Mac installer ads hide behind Bing redirects to run ClickFix commands
Malware

Illustrative image generated with AI

A malvertising campaign is using Google search ads that display a bing.com address to steer Mac users toward a counterfeit Claude download page. According to BleepingComputer's account of research by Push Security, the page tricks visitors into pasting a malicious command into Terminal. What that command ultimately installs has not been established.

How the ad gets past the eye test

Push Security found the campaign after its researchers spotted a malicious Google ad aimed at people searching for "claude mac." The reports do not say when that happened.

The attackers exploit a legitimate Bing click-tracking endpoint, bing.com/ck/a, as the destination of the ad. Because the ad shows a bing.com domain rather than an attacker-controlled one, it looks less suspicious to the user. Push Security calls the technique "Adception."

The reported click path runs as follows:

  1. The user clicks the Google ad and passes through Google's ad redirect.
  2. The request reaches bing.com/ck/a, which uses JavaScript to forward the browser.
  3. The browser lands on a legitimate but compromised WordPress site belonging to a South American retailer. The source does not name the retailer.
  4. That site sends the visitor on to claude-desk-code[.]com, the fake Claude download page.

Cloaking to avoid scrutiny

The chain is built to show its payload only to intended targets. According to Push, the compromised WordPress site checks for a Bing referrer and specific browser headers before redirecting. The fake Claude page then uses JavaScript to confirm the visitor came from Google or Bing. Anyone who opens the malicious domain directly sees a 404 error page, which makes casual checks and some automated analysis less likely to find anything.

A legitimate command on screen, a different one on the clipboard

The fake page imitates a Claude download page for macOS. It displays the genuine installation command used by Anthropic's installer: curl -fsSL https://claude.ai/install.sh | bash.

The copy button, however, places a different command on the clipboard. Per Push Security, the substituted command prints a message saying Claude is being downloaded from Anthropic's official website. In the background it decodes a Base64-encoded URL pointing to lake-90[.]com, silently fetches a .dat file with curl, and pipes it straight into the macOS Z shell (zsh).

A victim who looks at the page, or at the terminal output, therefore sees the legitimate Claude URL while a different script runs. This is the core of a ClickFix attack: the user executes the malicious step themselves, so it does not depend on a software vulnerability.

Wider toolkit, unknown payload

Push Security identified several other domains tied to the same ClickFix toolkit, which it tracks internally as AcSig. They share the same macOS installation command, payload URL structure and installer interface. The source does not name those domains.

The final payload is unknown. The reporting does not establish what malware, if any, the downloaded script installs, and it gives no victim count or severity rating. No statements from Google, Microsoft, Anthropic or the compromised retailer are included.

What readers can do

The source offers no vendor guidance. The mechanics point to some practical steps:

  • Do not paste commands copied from a web page into Terminal, especially after reaching the page through a sponsored result.
  • Compare what you pasted with what the page displayed before pressing Enter. The two can differ.
  • Download software from the vendor's official domain, typed or bookmarked, rather than through an ad.
  • Search your environment for the reported indicators: claude-desk-code[.]com and lake-90[.]com, plus curl requests fetching .dat files that are piped into zsh.

Security dossiers

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →