What happened
Push Security detected a multi‑stage phishing attack that begins with a Google Search ad for the term “claude mac”. The ad’s displayed URL is bing.com, and clicking it triggers Bing’s click‑tracking redirect (bing.com/ck/a) which forwards the browser to a compromised WordPress site belonging to a South American homeopathy retailer. That site checks for a Bing referrer and specific headers before serving a cloaked page that mimics Anthropic’s Claude download page. The page shows the legitimate curl command for Claude’s installer, but the copy‑to‑clipboard button places a malicious command that pulls a script from lake‑90.com and executes it via zsh. The malicious payload is only delivered when the full redirect chain is followed, evading many URL‑based scanners that see only the trusted intermediate domains (Google, Bing, the retailer). Push’s browser‑native AI security platform identified the attack in a customer environment and is now hunting for similar “Adception” chains across its client base.
Push Security’s monitoring flagged a Google‑sponsored ad for "claude mac" that listed bing.com as the destination domain. The ad passed Google’s ad review because the final URL was another search engine, not a known malicious site.
Clicking the ad sent the browser to Bing’s click‑tracking redirect (bing.com/ck/a) which encodes the next URL in a base64 parameter. The redirect returned a 200 response with JavaScript that preserved the Bing referrer.
The encoded URL pointed to a compromised WordPress site (homeopatiaalemana.com/quienes-somos/). That site performed a server‑side check for a Bing referrer and specific headers before serving a cloaked page that looked like Anthropic’s Claude download page.
The fake Claude page displayed the legitimate curl command for Claude’s installer, but the copy‑to‑clipboard button placed a malicious command that fetched a script from lake‑90.com and executed it via zsh. The script printed a message "Downloading Claude: https://claude.ai/install.sh" to disguise its activity.
Push’s AI‑native browser security tool captured the full session, identified the malicious clipboard event, and blocked the payload. The company is now hunting for similar chains across its customer base.
Source details: pushsecurity.com ↗
Why it matters
The campaign demonstrates how attackers can exploit trusted advertising and search‑engine infrastructure to bypass conventional phishing defenses. By the malicious payload behind a chain of reputable domains, the attack evades email gateways, URL reputation filters, and ad‑review processes that typically block direct malicious links. The use of a fake Claude installer is significant because Claude is a high‑profile AI assistant; compromising its download page can give attackers a foothold on users’ machines and potentially harvest credentials or exfiltrate data from AI‑driven workflows. This technique raises broader concerns for AI‑tool security, as many enterprises allow employees to install AI assistants on corporate devices. The incident also highlights the need for real‑time, session‑level detection rather than reliance on static IoCs, which quickly become obsolete when attackers rotate domains.
The attack leverages trusted ad and search‑engine infrastructure, making it harder for traditional URL‑based filters to detect the malicious payload.
By targeting Claude’s installer, the campaign exploits the trust users place in AI tools, potentially compromising devices that handle sensitive corporate data.
The multi‑hop chain shows that static IoC lists are insufficient; real‑time telemetry that follows the entire browser session is required for effective detection.
If left unchecked, similar techniques could be used to distribute malware disguised as other AI assistants, expanding the attack surface for enterprises adopting .
Interactive Mechanism: How It Actually Works
Explore the underlying technology behind this development interactively.
Why can ethical evaluation not be reduced to one model score?
What to watch next
Security teams should monitor for similar ad‑based redirect chains that involve AI tool download pages, especially for Claude, ChatGPT, or other LLM clients. Organizations using Push Security or comparable browser‑telemetry solutions may see increased alerts for “Adception” patterns. Vendors of ad platforms (Google, Microsoft/Bing) may need to tighten review of destination URLs that point to other search engines or third‑party sites. Users should verify download commands directly from official AI provider sites and avoid copying commands from web pages, even when they appear authentic. Future research may explore automated detection of multi‑hop redirect abuse in real time.
Increased reports of ad‑based malvertising that uses search‑engine redirects to deliver malicious AI‑tool installers.
Potential policy changes by Google and Microsoft to require deeper vetting of ad destinations that point to other search engines or third‑party domains.
Adoption of browser‑level security solutions that can monitor full session telemetry and detect clipboard‑based payload delivery.
User education campaigns emphasizing verification of download commands directly from official AI provider sites.