In a sophisticated evolution of malvertising, cybersecurity researchers have uncovered a cunning campaign that leverages the reputation of major search engines to bypass traditional advertising safeguards. Dubbed "Adception" by the threat intelligence team at Push Security, the attack chain utilizes legitimate Bing search-result redirects to mask malicious destinations within Google search ads, ultimately tricking macOS users into executing stealthy, credential-stealing commands.
This discovery highlights a growing trend in the threat landscape: the exploitation of "trusted" infrastructure to lend an air of legitimacy to malicious campaigns, making it increasingly difficult for both automated security filters and vigilant users to discern safe content from digital traps.
Main Facts: The Anatomy of a Deceptive Ad
The core of the "Adception" campaign relies on a multi-stage redirection architecture designed to exploit the trust users and security scanners place in established tech giants. When a user searches for "Claude mac" on Google, they are presented with a sponsored result that appears to lead to a legitimate, safe destination.
The Trust-Washing Technique
In a typical malvertising attack, users are often directed to domains that mimic legitimate brands through typosquatting or lookalike URLs. Adception, however, changes the game by using a legitimate bing.com click-tracking endpoint as the destination URL for a Google ad. By leveraging Bing’s trusted domain, the attackers successfully bypass initial advertising security checks, as the ad’s "destination" appears to be an authoritative source of truth.
Once a user clicks on the seemingly benign ad, the traffic is routed through a series of redirects:

- Google Ad Redirect: The initial landing mechanism for the paid search result.
- Bing Click-Tracker: The user is passed through
bing.com/ck/a, the engine’s internal redirect mechanism. This masks the true destination and imbues the traffic with the credibility of a Bing referral. - Compromised WordPress Site: The traffic is funneled through a legitimate, but compromised, WordPress site belonging to a South American retailer. This acts as a middle-man to filter traffic.
- The Malicious Payload Site: Finally, the user lands on
claude-desk-code[.]com, a high-fidelity replica of an official Claude download page.
Chronology of the Attack Chain
To understand how Adception operates, one must look at the progression from the initial search query to the point of compromise.
Stage 1: Discovery and Targeting
The campaign was identified when researchers observed a sponsored ad on Google targeting users searching for the macOS version of Claude, the popular AI assistant developed by Anthropic. By bidding on specific keywords related to productivity software, the attackers ensure that their ads are served to high-intent users who are actively looking to install legitimate software.
Stage 2: The Cloaking and Filtering Layer
The attackers employ sophisticated cloaking techniques to ensure that their infrastructure remains hidden from prying eyes. The compromised WordPress site acts as a gatekeeper. It inspects incoming traffic, looking for specific HTTP headers and a Bing-based referrer. If the visitor does not meet these criteria—such as in the case of a security researcher or an automated bot—the site serves a 404 error page, effectively going "dark" to defensive tools.
Stage 3: The "ClickFix" Execution
Once the user reaches the final malicious page, they are greeted by a professional-looking interface mimicking the official Anthropic download experience. The site instructs the user to copy an installation command into their Terminal.
The command displayed to the user is a legitimate, benign command: curl -fsSL https://claude.ai/install.sh | bash. However, the page utilizes a "ClickFix" technique. When the user clicks the "Copy" button, the JavaScript on the page invisibly substitutes the benign command in the user’s clipboard with a malicious one.

Stage 4: Execution of the Payload
The substituted command is designed to deceive the user by printing a message that mimics a legitimate installation process. Behind the scenes, however, it decodes a Base64 string that points to a server at lake-90[.]com. It then uses curl to fetch a .dat file and pipes it directly into the macOS zsh shell. Because the user is looking at a legitimate installation URL in their terminal window, they remain unaware that they are executing arbitrary code provided by the attackers.
Supporting Data: The "AcSig" Toolkit
Push Security has linked this campaign to an internal threat cluster they call "AcSig." The researchers discovered several other domains sharing the same infrastructure, payload structure, and "ClickFix" user interface. This suggests that the attackers are running a "malware-as-a-service" operation or are highly organized, capable of rapidly deploying new landing pages as soon as existing ones are flagged or taken down.
The persistence of this campaign is further evidenced by the use of legitimate but compromised websites. By hijacking the infrastructure of innocent parties—such as the South American retailer identified in the report—the attackers gain a temporary "reputation boost" that helps them avoid blacklisting by reputation-based security services.
Official Responses and Industry Context
While neither Google nor Microsoft has issued a public statement regarding the specific exploitation of their respective redirect endpoints in this campaign, the industry at large is grappling with the broader implications of malvertising.
Security professionals often refer to this as a "platform abuse" problem. Because search engines must allow for click-tracking and redirection to provide their core services, these features are inherently difficult to disable without breaking the user experience. Instead, companies are increasingly relying on behavioral analysis and machine learning to identify anomalous redirect chains that deviate from standard user patterns.

Anthropic, the developer of Claude, has consistently warned users to download software only from official sources (claude.ai). They reiterate that the company does not use complex, multi-stage redirect chains to facilitate software installations and that users should always verify the contents of their clipboard before pasting commands into a system terminal.
Implications for Users and Organizations
The Adception campaign serves as a stark reminder that the "search engine" is no longer an inherently safe gateway to the internet. As attackers refine their methods, the burden of security shifts further toward the end-user and the enterprise.
For Individual Users
- Clipboard Awareness: Never blindly paste commands into a terminal, especially when the command is copied from a website using a "click-to-copy" button. Always inspect the contents of the clipboard in a plain-text editor first.
- Source Verification: Even if a search result appears at the top of the page with a "Sponsored" label, verify the URL. If the URL looks overly complex or redirects through multiple domains, avoid it.
- Official Sources: Bookmark the official websites of the software you use. Rather than searching for "Download [Software Name]," go directly to the trusted URL.
For Enterprise Defenders
- Egress Filtering: Organizations should implement strict egress filtering to prevent unauthorized scripts from reaching out to unknown or unclassified external domains.
- Terminal Monitoring: Endpoint Detection and Response (EDR) solutions should be configured to alert on suspicious shell activity, such as piping
curlorwgetcommands directly intosh,bash, orzsh. - Security Awareness Training: The "Adception" attack is a prime example of why employees must be trained not just on phishing emails, but on the dangers of search engine manipulation. Educating staff on the mechanics of "ClickFix" can prevent a catastrophic breach.
The Future of "Adception" Attacks
The rise of AI-powered attacks and increasingly sophisticated malvertising suggests that we are entering a new era of cyber threats where the infrastructure of the internet is turned against its users. The "Adception" campaign is likely just the beginning. As security researchers at Push Security and other firms continue to shine a light on these techniques, the cat-and-mouse game between attackers and platform providers will intensify.
The ultimate takeaway from this campaign is that trust is a vulnerability. When an attacker can successfully "borrow" the reputation of Bing and the visibility of Google to deliver a payload, the traditional perimeter-based security model becomes insufficient. Defenders must now assume that even the most trusted search results could lead to compromise, and users must adopt a "zero-trust" approach to the content they encounter online.
As the industry moves toward more robust validation techniques, the focus will undoubtedly shift toward real-time analysis of the end-to-end user journey. Until then, the most effective defense remains the critical eye of the user and a healthy skepticism toward the digital shortcuts offered by search engines.








