As reported by BleepingComputer, researchers at Push Security have documented a malvertising campaign they've dubbed "Adception" — a layered abuse of Google Ads and Bing's click-tracking redirect infrastructure to deliver fake Claude installers carrying ClickFix clipboard-hijacking payloads targeting macOS users.

Threat Alert: As reported by BleepingComputer, researchers at Push Security have documented a malvertising campaign they've dubbed "Adception" — a layered abuse of Google Ads and Bing's click-tracking redirect infrastructure to deliver fake Claude installers carrying ClickFix clipboard-hijacking payloads targeting macOS users.

The core innovation here isn't the payload — ClickFix attacks that substitute clipboard contents with malicious shell commands have been circulating for months. What's notable is the delivery mechanism and what it reveals about the trust assumptions underlying ad-platform security.

Why This Attack Chain Is Significant

The attack exploits a fundamental tension in digital advertising: platforms verify the destination URL shown to users and reviewers, but the actual redirect path can be layered through multiple legitimate intermediaries. By submitting bing.com/ck/a as the ad click URL, the attacker leverages Microsoft's own tracking infrastructure — a domain that virtually every ad-review system will treat as trusted. The Bing redirect then points to a compromised WordPress site that, in turn, forwards to the malicious payload host.

This creates a chain where each hop looks legitimate in isolation:

Why This Attack Chain Is Significant
Google Ads sees bing.com as the destination — a top-tier trusted domain
Bing's redirect sees a Google ad referrer and processes the click normally
The compromised WordPress site only redirects visitors with a Bing referrer and specific headers, cloaking itself from scanners
The fake Claude page verifies arrival from Google or Bing before displaying the payload, redirecting everyone else to a 404
The result: automated ad-review systems, manual reviewers, and security scanners that attempt direct access all see different things — and only the intended victim reaches the malicious payload.

The ClickFix Angle: Social Engineering at the Terminal

The final-stage payload exploits a particularly dangerous interaction pattern. Users searching for "claude mac" are already primed to follow installation instructions. The fake page displays Anthropic's legitimate curl | bash install command but, when the copy button is clicked, places a different, malicious command in the clipboard. The victim then pastes it into Terminal themselves — effectively executing the attack with their own hands.

This is especially difficult for endpoint security to intercept because the command execution originates from the user's own terminal session, not from a dropped binary or injected process. From a monitoring perspective, it can look like normal user behavior.

Broader Implications: AI Brand Abuse Is Escalating

This campaign fits a clear pattern of threat actors pivoting to AI-adjacent brands as lures. Claude, ChatGPT, and similar tools have massive search demand, users expect to run installers, and the audience skews toward developers comfortable with terminal commands — making them both reachable via technical lures and potentially holding high-value credentials and source code access.

Expect this technique to proliferate. The Bing redirect trick is not novel in concept, but its weaponization in this specific ad-platform context is now publicly documented, which typically accelerates adoption by other threat groups.

What You Should Do

For Security Teams

  • Detect the redirect chain: Monitor egress traffic for sequences involving bing.com/ck/a followed by rapid redirects to previously unseen domains, especially from corporate-managed browsers
  • Harden endpoint policies: Evaluate whether curl | bash patterns from user terminals should trigger EDR alerts in your environment — legitimate use exists but is infrequent
  • Block clipboard-execution patterns: Where supported, enable macOS Endpoint Security features that flag clipboard-to-Terminal command sequences matching known ClickFix signatures
  • Ad-platform awareness: If your organization runs ads, understand that competitors or attackers can bid on your brand terms and that platform review processes have demonstrable blind spots with redirect-based evasion

For Individuals and Developers

  • Verify install URLs manually: Always confirm that the download page matches the official domain (claude.ai, anthropic.com) — never trust a Google Ad as the source of truth
  • Inspect clipboard contents: Before pasting any install command into Terminal, paste it into a text editor first to verify the content matches what the page displayed
  • Treat sponsored results with skepticism: For software downloads specifically, navigate directly to the vendor's website rather than clicking through ads

The underlying lesson is structural: trust signals in the ad-tech ecosystem — domain reputation, platform review, SSL certificates — are increasingly being gamed by attackers who understand how to chain legitimate services into malicious funnels. Defenders need to stop treating "trusted domain" as a sufficient indicator of safety and start validating the complete redirect path, not just the entry point.