Hackers are abusing legitimate Bing click-tracking redirects embedded in Google Ads to push fake Claude installers that execute ClickFix attacks. Security researchers labeled the technique "Adception." A sponsored Google ad points to bing.com/ck/a, which forwards users to a compromised WordPress retailer site and then to a fake claude-desk-code.com download page. Because the visible ad destination is bing.com, the ad bypasses advertising security checks and appears trustworthy. Bing's JavaScript-based click tracking lets attackers forward users while making the traffic look like it originates from Bing.
The operation uses multi-layer cloaking: the compromised WordPress site checks for a Bing referrer and specific headers before redirecting, and the fake Claude page verifies arrival from Google or Bing and returns a 404 to direct visitors or scanners. The fake installer displays Anthropic’s legitimate curl command, but the copy button places a malicious Base64-decoded command into the clipboard that fetches a .dat file from an attacker server (lake-90.com) and pipes it to zsh for execution. Researchers tied multiple domains with an identical macOS installer pattern to a ClickFix toolkit tracked as AcSig; the final payload remains unknown, but the campaign creates a covert, ad-driven macOS execution vector that evades normal scanning and trust signals.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.