A malicious Google ad used a trusted Bing URL to direct Mac users to a fake Claude installation page. The page's copy button did not copy the command it displayed to the clipboard, but instead copied a different code that downloaded and executed an unknown file.

The chain was discovered by cybersecurity firm Push Security after its researchers saw a sponsored result for the search term “claude mac.” The ad indicated bing.com as the destination, and then the route went through the website of a legitimate business in South America, which the perpetrators had compromised.
The technique leverages a redirect that is commonly used to track clicks. The link appears to come from a well-known search engine before the compromised website sends the visitor to a fake download page. Push calls the method “Adception.”.
This malicious ad is not linked to a breach of Google or Microsoft's systems. The researchers describe the misuse of redirects and a third-party website, not access to the infrastructure of the two companies. The incident shows that a well-known link does not guarantee a safe destination.
How malicious advertising exploits Bing
According to Push Security's analysis, the malicious ad first went through Google's ad service and then through Bing's click tracking engine. From there, the browser was directed to the "About" page of a real commercial website that the attackers had compromised.
The compromised website checked the origin of the visit and certain browser details before proceeding. The final page also checked whether the user had arrived from Google or Bing. Anyone opening the address directly could end up with an error, a technique that makes it difficult to analyze the threat.
The page mimicked the look of the Claude macOS installation page and displayed a legitimate Anthropic command. The trap was in the copy button: instead of the text the user saw, the button saved a different command to the clipboard. The attack therefore relied not only on the similarity of the web page, but also on the trust that copying would preserve the visible content.

When the user pasted the command into Terminal, it displayed a misleading message and then decoded a hidden address. The command downloaded a file from there and sent its contents to the macOS shell for execution. For security reasons, we are not reproducing the command or the attack indicators here.
Push Security said it had identified multiple addresses linked to the same ClickFix toolkit, which it monitors under the name AcSig. The campaign in question, however, has not been publicly linked to a known cybercrime group. The information available relates to the technique and delivery chain, not the identity of the perpetrators.
BleepingComputer's report points out a critical limitation to the findings: the researchers haven't determined exactly what the final file contained. It hasn't been confirmed whether specific malware was installed or whether there were any victims. Therefore, there is no substantiated claim of data theft or device infection.
Why the copy button is the danger point
The ClickFix method convinces the user to perform an action themselves that is presented as necessary to install or fix a problem. In this case, the request to paste into Terminal turns a visit to an ad into an immediate code execution. The page may look convincing, but the command does not come from the official service.
The trick is particularly deceptive because the screen and clipboard do not agree. Even a careful user can see the correct text on the page and believe that it is exactly what they are copying. Therefore, the appearance of an official website or a valid address in the path does not in itself constitute verification of the command.

The incident is part of a wider series of ClickFix attacks, in which attackers convince users to execute malicious commands themselves. The trap remains the same: a seemingly ordinary instruction transfers the threat from the website to the visitor's computer.
See also: Hiding malicious code in the browser cache
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What to look out for in malicious software advertising
To download AI tools, type in the official address yourself or follow the link from the manufacturer's website. Don't take a sponsored result as proof of authenticity. If a page asks you to open Terminal and paste a command, stop and check where the instruction is coming from.
The SecNews technical team recommends checking every command in a plain text editor before executing it, especially when it comes from a copy button on an unknown page. If a suspicious command has already been executed, do not use the device to log in to accounts; contact an IT specialist and change passwords from another, clean device.
See also: More than 100 pages with fake Cloudflare control distribute LunexStealer
The incident reminds us that a convincing appearance and a familiar link do not guarantee that the text in the clipboard is the same as what the user sees on the screen. The safest option is to not execute a command from an unverified page, even when it is presented as a simple installation.
See also: Previous campaign with fake Claude via Google ads
