Skip to content
by InfinyAI ES

IA en un minutoNewsSecurity

Security

A Google ad routes through Bing to a fake Claude download for Mac

IA en un minuto newsroom · Editor: Jon Elgezabal

In 30 seconds

Push Security has documented a Google ad that showed people searching for Claude for Mac a Bing domain and ended on a fake download page after crossing Bing and a compromised retailer. The page shows the genuine Anthropic command, yet its copy button hands over another that fetches and runs an outside script. It is still unknown what that script installs.

Push Security, a browser security company, published on Friday, October 9, its analysis of a scam that starts with an ordinary search. A Google search for "claude mac" returned a sponsored result whose listed domain was bing.com, not a Claude lookalike or anything resembling Anthropic. The company calls the technique, not entirely seriously by its own account, "Adception".

The click went through four hops. First, Google's ad-click redirect. Then the redirect Bing puts behind every result on its own search pages to log clicks. From there, the "about us" page of a South American homeopathy retailer, legitimate but compromised. And finally, a polished copy of a Claude download page. According to Push, Google's ad review approved a destination that was simply another search engine.

Push says Bing's click-tracking redirect had turned up before in phishing emails and QR codes, but that it had not seen it used as the destination of a search ad and found no prior public reporting of that. The link in this campaign contains a timestamp that decodes to October 5, 2026, which is probably when Bing generated it.

The fake page offers to install Claude on macOS with a command for the Terminal (the Mac app for typing commands) and displays Anthropic's real command. The copy button, however, places a different one on the clipboard. Once pasted, the Terminal prints that it is downloading Claude from claude.ai, but, as BleepingComputer, a security news outlet, details, it silently downloads a file from an attacker-controlled server and pipes it into the macOS shell to run it. A user who reads the page and then watches the Terminal sees a legitimate address both times.

The setup also has two filters to stay hidden. The compromised site only forwards visitors who arrive from Bing with certain browser headers, and the fake page sends anyone who does not come from Google or Bing to a 404 error, so opening the address directly shows nothing.

It is not known what the script installs. BleepingComputer notes that the final payload remains unknown and that it is unclear what malware, if any, is being installed. Push has found several domains that use the same toolkit and says that four in five ClickFix attacks it detects (the user copies and pastes a malicious command) reach victims through search engines. It adds that most attackers do not even bother to mask the domain shown in the ad, and that if this trick helps a scheme stay off Google's radar a little longer, it is a low-cost step more attackers will probably adopt.

Push detected the case in a customer environment.

Why it matters · analysis and opinion

The practical lesson is an uncomfortable one: checking the domain on the ad is no longer enough, because here the domain was trustworthy and so was everything shown on screen. What fails is the habit of installing software by copying a command from a website reached through a search engine. In an office with Mac computers, the cheapest measure is to set a rule: tools get installed by typing the vendor's official address by hand or from a saved bookmark, never from a sponsored result, and no command is pasted into the Terminal without reading it first in a text editor. Anyone who has pasted a command from a page like this should tell whoever looks after IT: it is still not known what the downloaded program does. Search engines' ad review, as this case shows, is no guarantee.

Official source: Push Security · Written with the help of AI: how we make the news

Is your website up to scratch? We will audit it for free

AI in your inbox, every day or every Friday

The stories that matter, each one in a minute. With the source for every one.

Choose one or both:

Sign up and you are in: the daily arrives every night and the weekly on Friday mornings. You can unsubscribe from any email.