Adception Google Ads and Bing redirect Claude ClickFix campaign
Campaign
Summary
Hide ▲
Show ▼
A malvertising campaign is abusing Google Ads and Bing redirect chains to push fake Claude installers that try to trigger malicious command execution on macOS users. The operation uses multi-layer cloaking and a compromised WordPress site to hide the lure from scanners. The final page copies Anthropic's legitimate install flow but swaps the clipboard command for a script that fetches payload data from lake-90[.]com and executes it through zsh. Researchers track the associated toolkit as AcSig, and the ultimate payload remains unknown.
Related Happenings
Third-party.com fake Cloudflare verification ClickFix campaign targeting Windows users
Campaign
H score24
First: 24.09.2026 01:46
Last: 24.09.2026 01:46
Sources 1
About this happening:
The third-party.com domain is hosting a ClickFix lure that impersonates a Cloudflare security check and pushes Windows users to run malicious PowerShell comman...
Third-party.com fake Cloudflare verification ClickFix campaign targeting Windows users
CampaignAbout this happening: The third-party.com domain is hosting a ClickFix lure that impersonates a Cloudflare security check and pushes Windows users to run malicious PowerShell comman...
Latest development: 24.09.2026 18:27
Manifold Security says third-party[.]com has served a ClickFix lure to Windows browsers since at least June 2026, and the broader abuse now extends to 13 additional non-IANA-reserved placeholder domains, including yoursite[.]com and your-domain[.]com, which show scams and scareware to macOS visitors while serving ordinary parking pages to other users.
PasteSwitch ClickFix malware delivery of MacSync, AMOS helper, and Amatera Stealer
Malware Activity
H score30
First: 14.09.2026 21:34
Last: 14.09.2026 21:34
Sources 1
About this happening:
PasteSwitch continues to use ClickFix-style social engineering to push MacSync and related payloads onto Windows and macOS systems, with a prior HBO Max Re...
PasteSwitch ClickFix malware delivery of MacSync, AMOS helper, and Amatera Stealer
Malware ActivityAbout this happening: PasteSwitch continues to use ClickFix-style social engineering to push MacSync and related payloads onto Windows and macOS systems, with a prior HBO Max Re...
Latest development: 24.09.2026 23:53
Kaspersky identified a MacSync campaign targeting macOS that uses public iCloud calendar events to hide commands in the DESCRIPTION: line, fetch a next-stage archive from iCloud, and reach the malware through an APP bundle dropper. The same campaign also adds an Objective-C backdoor that disguises itself as Finder, establishes persistence through LaunchAgent, .zshrc modifications, and global Git hooks, and can run attacker-supplied AppleScript or replace an installed Ledger wallet app.
SectopRAT fake Claude installer delivery
Malware Activity
H score19
First: 23.07.2026 22:48
Last: 23.07.2026 22:48
Sources 1
About this happening:
The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. T...
SectopRAT fake Claude installer delivery
Malware ActivityAbout this happening: The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. T...
ChatGPT and Claude phishing and malvertising campaign
Campaign
H score36
First: 01.06.2026 12:30
Last: 01.06.2026 12:30
Sources 1
About this happening:
The ChatGPT- and Claude-themed phishing and malvertising campaign is actively steering users to fake download pages that can deliver malware. Attackers are using Goo...
ChatGPT and Claude phishing and malvertising campaign
CampaignAbout this happening: The ChatGPT- and Claude-themed phishing and malvertising campaign is actively steering users to fake download pages that can deliver malware. Attackers are using Goo...
Openew[.]app cloaked malware download portal
Malware Activity
H score26
First: 29.05.2026 21:21
Last: 29.05.2026 21:21
Sources 1
About this happening:
The openew[.]app malware-delivery activity now also uses legitimate ChatGPT shared pages as the first lure, with Google ads and SEO poisoning sending victims to a...
Openew[.]app cloaked malware download portal
Malware ActivityAbout this happening: The openew[.]app malware-delivery activity now also uses legitimate ChatGPT shared pages as the first lure, with Google ads and SEO poisoning sending victims to a...
Timeline
-
09.10.2026 23:31 2 articles · 1h ago
Google Ads abuse Bing redirects to deliver fake Claude installers
Initial DisclosurePush Security identified a malvertising campaign targeting people searching for "claude mac" in which Google search ads use legitimate Bing click-tracking redirects to lead to a compromised WordPress site and then to claude-desk-code[.]com, a fake Claude download page for macOS users. The lure uses cloaking checks for Bing referrers and browser headers, and the copy-button flow swaps Anthropic's legitimate installation command for a malicious command that decodes a Base64 URL, fetches a .dat file from lake-90[.]com, and executes it through zsh; the final payload remains unknown. Push Security tracks the related ClickFix toolkit internally as AcSig and says several domains share the same macOS installation command, payload URL structure, and installer interface.
Show sources
- Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks — www.bleepingcomputer.com — 09.10.2026 23:31
- Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks — www.bleepingcomputer.com — 09.10.2026 23:31