Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Hackers Exploit Google Ads and Bing Redirects in “Adception” Campaign to Deliver Malicious Claude Installer (ClickFix)

Researchers uncovered a malvertising campaign that uses Google Search ads and Bing click‑tracking redirects to serve a fake Claude macOS installer. The technique bypasses ad‑network security checks, underscoring the need for continuous vendor‑risk monitoring and auditable redirect logging.

LiveThreat™ Intelligence · 📅 October 10, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

Hackers Exploit Google Ads and Bing Redirects in “Adception” Campaign to Deliver Malicious Claude Installer (ClickFix)

What Happened — Researchers at Push Security identified a malvertising campaign that leverages legitimate Google Search ads and Bing click‑tracking redirects (“Adception”). The ads point to a Bing domain, which then forwards the browser to a compromised WordPress site that ultimately serves a fake Claude macOS installer. The installer copies a malicious command to the clipboard, leading to the download and execution of additional payloads.

Why It Matters for Trust & Control Assurance

  • The technique subverts trusted third‑party services (Google Ads, Bing) to bypass ad‑network security checks, highlighting the need for continuous monitoring of vendor‑provided traffic.
  • Demonstrates how insufficient oversight of advertising supply chains can create blind spots in an organization’s evidence of due diligence and audit readiness.
  • Aligns with the control objective of third‑party risk management: verifying that external platforms enforce robust security controls and that any redirection behavior is logged and reviewed.

Who Is Affected — Advertising platforms, publishers using third‑party ad networks, and macOS end‑users who click on search‑engine ads.

Recommended Actions

  • Incorporate ad‑network traffic into your continuous vendor‑risk monitoring program; capture redirect chains and validate destination domains.
  • Enforce strict logging of third‑party redirects and perform regular audits of ad‑placement policies.
  • Deploy web‑gateway or DNS filtering that flags unexpected Bing or Google referrers leading to non‑whitelisted domains.

Source: BleepingComputer

Technical Notes

  • Attack vector: malicious ad redirects (malvertising) using legitimate Bing click‑tracking endpoint (bing.com/ck/a).
  • Payload delivery: fake Claude installer that replaces the legitimate curl -fsSL https://claude.ai/install.sh | bash command with a malicious Base64‑encoded URL pointing to lake-90.com.
  • Cloaking checks for specific referrer headers and browser signatures to evade scanners.

Source: Push Security Report

📰 Original Source
https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-bing-redirects-to-push-claude-clickfix-attacks/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →