Hackers Exploit Google Ads and Bing Redirects in “Adception” Campaign to Deliver Malicious Claude Installer (ClickFix)
What Happened — Researchers at Push Security identified a malvertising campaign that leverages legitimate Google Search ads and Bing click‑tracking redirects (“Adception”). The ads point to a Bing domain, which then forwards the browser to a compromised WordPress site that ultimately serves a fake Claude macOS installer. The installer copies a malicious command to the clipboard, leading to the download and execution of additional payloads.
Why It Matters for Trust & Control Assurance
- The technique subverts trusted third‑party services (Google Ads, Bing) to bypass ad‑network security checks, highlighting the need for continuous monitoring of vendor‑provided traffic.
- Demonstrates how insufficient oversight of advertising supply chains can create blind spots in an organization’s evidence of due diligence and audit readiness.
- Aligns with the control objective of third‑party risk management: verifying that external platforms enforce robust security controls and that any redirection behavior is logged and reviewed.
Who Is Affected — Advertising platforms, publishers using third‑party ad networks, and macOS end‑users who click on search‑engine ads.
Recommended Actions
- Incorporate ad‑network traffic into your continuous vendor‑risk monitoring program; capture redirect chains and validate destination domains.
- Enforce strict logging of third‑party redirects and perform regular audits of ad‑placement policies.
- Deploy web‑gateway or DNS filtering that flags unexpected Bing or Google referrers leading to non‑whitelisted domains.
Source: BleepingComputer
Technical Notes
- Attack vector: malicious ad redirects (malvertising) using legitimate Bing click‑tracking endpoint (
bing.com/ck/a). - Payload delivery: fake Claude installer that replaces the legitimate
curl -fsSL https://claude.ai/install.sh | bashcommand with a malicious Base64‑encoded URL pointing tolake-90.com. - Cloaking checks for specific referrer headers and browser signatures to evade scanners.
Source: Push Security Report