"The technique, dubbed 'Adception' by security researchers at Push Security, appears designed to evade advertising security checks by using Bing's trusted domain as the ad destination." That description captures the core of a recent campaign in which malicious actors used legitimate search-ad and redirect infrastructure to lead macOS users to a fake Claude installer that substitutes a harmful command for Anthropic's real install line.
How the Adception chain used Google Ads, Bing click-tracking, and a compromised retailer site
Push Security discovered the campaign after detecting a malicious Google ad targeting users searching for "claude mac." Rather than pointing directly at an attacker-controlled domain, the sponsored result displayed the legitimate bing.com domain. When clicked, the ad passed through Google's advertising redirect and then reached Bing's click-tracking endpoint at bing.com/ck/a. That click-tracking endpoint forwarded the browser to a legitimate but compromised WordPress website belonging to a South American retailer. The compromised retailer site then redirected visitors onward to the attacker-controlled landing page hosted at claude-desk-code[.]com.
According to Push Security, the use of Bing's click-tracking made the advertisement appear less suspicious while still allowing attackers to reach a malicious destination. Bing's click-tracking redirects use JavaScript to send visitors to their destination, permitting attackers to redirect users to malicious websites while making the traffic appear to originate from Bing.
Tactics to avoid automated detection: two layers of cloaking
The campaign relied on multiple, deliberate cloaking steps to prevent security scanners and direct visitors from seeing the payload. The compromised WordPress site checked for a Bing referrer and specific browser headers before issuing its redirect; only visitors coming through the expected path were forwarded. The fake Claude website at claude-desk-code[.]com also used JavaScript to verify that visitors arrived from Google or Bing. Visitors who tried to access the malicious site directly were redirected to a 404 error page, a behavior Push Security says hinders automated analysis.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleThe fake installer: visible truth, hidden command
The final landing page is a convincing imitation of a Claude download page that offers a macOS installer implemented as a Terminal command. The page displayed Anthropic's legitimate installation command — curl -fsSL https://claude.ai/install.sh | bash — but clicking the page's copy button placed a different, malicious command into the clipboard.
Push Security describes the substituted command as first printing a message that it is downloading Claude from Anthropic's official website, while actually decoding a Base64-encoded URL pointing to lake-90[.]com. The command then uses curl to silently download a .dat file from that attacker-controlled server and pipes the downloaded content directly into the macOS Z shell (zsh) for execution. Because the page shows the legitimate URL both on-screen and in the terminal prompt, victims can be misled into believing they executed the authentic installer even as an entirely different script runs.
ClickFix toolkit (AcSig) links multiple domains and leaves final payload unknown
Push Security identified several domains associated with the same ClickFix toolkit — internally tracked by the researchers as AcSig — that use an identical macOS installation command, the same payload URL structure, and the same installer interface. While the chain of redirection and the clipboard substitution are described in detail, Push Security reports the campaign's final payload remains unknown; it is therefore unclear what malware, if any, the attackers ultimately install.
How macOS users, security teams, and advertisers should view this campaign
- macOS users: The campaign targets users seeking a legitimate installer by substituting a copied command that looks correct but executes a different, Base64-decoded URL to lake-90[.]com and pipes a downloaded .dat file into zsh.
- Security teams and technologists: The attack combines ad redirects (Google), click-tracking (Bing's bing.com/ck/a), a compromised WordPress site, and two distinct cloaking checks (Bing referrer and browser headers; on-site JavaScript verifying arrival from Google or Bing), all designed to complicate automated detection and analysis.
- Advertisers and ad platforms: The use of a trusted bing.com click-tracking endpoint as the visible ad destination — a technique Push Security calls "Adception" — highlights how legitimate redirect infrastructure can be abused to mask malicious endpoints and evade advertisement security checks.
Push Security's report lays out a surgical, multi-stage abuse of advertising and redirect plumbing: a Google ad directing to bing.com, Bing's JavaScript click-tracker forwarding to a compromised retailer site, that site forwarding only when specific referrers and headers are present, and a final fake installer that substitutes a Base64-decoded URL to lake-90[.]com and executes its contents in zsh. Several domains tied to the ClickFix/AcSig toolkit share the same installer pattern, but the campaign's ultimate payload remains unidentified — a concrete gap the report leaves open and a next step for investigators and defenders alike.
Read the original Push Security report summary at BleepingComputer




