Find notable cyber news and cases, enriched with sources, timelines, and signals.

Adception Google Ads and Bing redirect Claude ClickFix campaign

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

A malvertising campaign is abusing Google Ads and Bing redirect chains to push fake Claude installers that try to trigger malicious command execution on macOS users. The operation uses multi-layer cloaking and a compromised WordPress site to hide the lure from scanners. The final page copies Anthropic's legitimate install flow but swaps the clipboard command for a script that fetches payload data from lake-90[.]com and executes it through zsh. Researchers track the associated toolkit as AcSig, and the ultimate payload remains unknown.

Related Happenings

Third-party.com fake Cloudflare verification ClickFix campaign targeting Windows users

Campaign
H score24 First: 24.09.2026 01:46 Last: 24.09.2026 01:46 Sources 1

About this happening: The third-party.com domain is hosting a ClickFix lure that impersonates a Cloudflare security check and pushes Windows users to run malicious PowerShell comman...

Latest development: 24.09.2026 18:27

Manifold Security says third-party[.]com has served a ClickFix lure to Windows browsers since at least June 2026, and the broader abuse now extends to 13 additional non-IANA-reserved placeholder domains, including yoursite[.]com and your-domain[.]com, which show scams and scareware to macOS visitors while serving ordinary parking pages to other users.

PasteSwitch ClickFix malware delivery of MacSync, AMOS helper, and Amatera Stealer

Malware Activity
H score30 First: 14.09.2026 21:34 Last: 14.09.2026 21:34 Sources 1

About this happening: PasteSwitch continues to use ClickFix-style social engineering to push MacSync and related payloads onto Windows and macOS systems, with a prior HBO Max Re...

Latest development: 24.09.2026 23:53

Kaspersky identified a MacSync campaign targeting macOS that uses public iCloud calendar events to hide commands in the DESCRIPTION: line, fetch a next-stage archive from iCloud, and reach the malware through an APP bundle dropper. The same campaign also adds an Objective-C backdoor that disguises itself as Finder, establishes persistence through LaunchAgent, .zshrc modifications, and global Git hooks, and can run attacker-supplied AppleScript or replace an installed Ledger wallet app.

SectopRAT fake Claude installer delivery

Malware Activity
H score19 First: 23.07.2026 22:48 Last: 23.07.2026 22:48 Sources 1

About this happening: The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. T...

ChatGPT and Claude phishing and malvertising campaign

Campaign
H score36 First: 01.06.2026 12:30 Last: 01.06.2026 12:30 Sources 1

About this happening: The ChatGPT- and Claude-themed phishing and malvertising campaign is actively steering users to fake download pages that can deliver malware. Attackers are using Goo...

Openew[.]app cloaked malware download portal

Malware Activity
H score26 First: 29.05.2026 21:21 Last: 29.05.2026 21:21 Sources 1

About this happening: The openew[.]app malware-delivery activity now also uses legitimate ChatGPT shared pages as the first lure, with Google ads and SEO poisoning sending victims to a...

Timeline

  1. 09.10.2026 23:31 2 articles · 1h ago

    Google Ads abuse Bing redirects to deliver fake Claude installers

    Initial Disclosure

    Push Security identified a malvertising campaign targeting people searching for "claude mac" in which Google search ads use legitimate Bing click-tracking redirects to lead to a compromised WordPress site and then to claude-desk-code[.]com, a fake Claude download page for macOS users. The lure uses cloaking checks for Bing referrers and browser headers, and the copy-button flow swaps Anthropic's legitimate installation command for a malicious command that decodes a Base64 URL, fetches a .dat file from lake-90[.]com, and executes it through zsh; the final payload remains unknown. Push Security tracks the related ClickFix toolkit internally as AcSig and says several domains share the same macOS installation command, payload URL structure, and installer interface.

    Show sources