Home › Intelligence › Brief
BREACH BRIEF 🟠 High ThreatIntel

Hackers Exploit Google Ads and Bing Redirects in “Adception” Campaign to Deliver Malicious Claude Installer (ClickFix)

Researchers uncovered a malvertising campaign that uses Google Search ads and Bing click‑tracking redirects to serve a fake Claude macOS installer. The technique bypasses ad‑network security checks, underscoring the need for continuous vendor‑risk monitoring and auditable redirect logging.

Verisq™ Intelligence · 📅 October 10, 2026 · 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

Hackers Exploit Google Ads and Bing Redirects in “Adception” Campaign to Deliver Malicious Claude Installer (ClickFix)

What Happened — Researchers at Push Security identified a malvertising campaign that leverages legitimate Google Search ads and Bing click‑tracking redirects (“Adception”). The ads point to a Bing domain, which then forwards the browser to a compromised WordPress site that ultimately serves a fake Claude macOS installer. The installer copies a malicious command to the clipboard, leading to the download and execution of additional payloads.

Why It Matters for Trust & Control Assurance

  • The technique subverts trusted third‑party services (Google Ads, Bing) to bypass ad‑network security checks, highlighting the need for continuous monitoring of vendor‑provided traffic.
  • Demonstrates how insufficient oversight of advertising supply chains can create blind spots in an organization’s evidence of due diligence and audit readiness.
  • Aligns with the control objective of third‑party risk management: verifying that external platforms enforce robust security controls and that any redirection behavior is logged and reviewed.

Who Is Affected — Advertising platforms, publishers using third‑party ad networks, and macOS end‑users who click on search‑engine ads.

Recommended Actions

  • Incorporate ad‑network traffic into your continuous vendor‑risk monitoring program; capture redirect chains and validate destination domains.
  • Enforce strict logging of third‑party redirects and perform regular audits of ad‑placement policies.
  • Deploy web‑gateway or DNS filtering that flags unexpected Bing or Google referrers leading to non‑whitelisted domains.

Source: BleepingComputer

Technical Notes

  • Attack vector: malicious ad redirects (malvertising) using legitimate Bing click‑tracking endpoint (bing.com/ck/a).
  • Payload delivery: fake Claude installer that replaces the legitimate curl -fsSL https://claude.ai/install.sh | bash command with a malicious Base64‑encoded URL pointing to lake-90.com.
  • Cloaking checks for specific referrer headers and browser signatures to evade scanners.

Source: Push Security Report

📰 Original Source
https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-bing-redirects-to-push-claude-clickfix-attacks/ ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →