LIVE · cybersecurity feed
Live wire
patch

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

A new malvertising campaign, dubbed "Adception" by security researchers at Push Security, is leveraging Google Ads and Bing redirects to distribute fake Claude installers that deploy "ClickFix" attacks. The campaign was identified after researchers observed malicious Google ads targeting users searching for "claude mac."

ZeroDay News ·

Source: BleepingComputer

A new malvertising campaign, dubbed "Adception" by security researchers at Push Security, is leveraging Google Ads and Bing redirects to distribute fake Claude installers that deploy "ClickFix" attacks. The campaign was identified after researchers observed malicious Google ads targeting users searching for "claude mac."

Unlike typical malvertising, the sponsored search results displayed the legitimate bing.com domain as the ad destination, which likely helped the ads bypass security checks and appear more trustworthy to users. When clicked, the ad first passed through Google's advertising redirect before reaching Bing's click-tracking endpoint, bing.com/ck/a. This endpoint then forwarded the browser to a compromised WordPress website belonging to a South American retailer.

The compromised WordPress site employed a multi-layered cloaking technique. It checked for a Bing referrer and specific browser headers before redirecting visitors to claude-desk-code[.]com, a fake Claude download page. The fake Claude website further verified that visitors originated from Google or Bing using JavaScript. Attempts to access the malicious site directly resulted in a 404 error, hindering analysis by automated security scanners.

The fake Claude download page is a convincing imitation, offering a macOS installer via a Terminal command. While the page displays Anthropic's legitimate installation command, `curl -fsSL https://claude.ai/install.sh | bash`, clicking the copy button places a malicious command into the clipboard.

The substituted command first prints a message claiming to download Claude from Anthropic's official website. However, it then decodes a Base64-encoded URL pointing to lake-90[.]com. This malicious script uses `curl` to silently download a `.dat` file from the attacker-controlled server and pipes its contents directly into the macOS Z shell (zsh) for execution. This sophisticated method ensures that victims see the legitimate Claude installation URL both on the download page and in their terminal, even as a different, malicious script is being executed.

The specific payload delivered by this attack remains unknown. However, Push Security has linked several domains to the same ClickFix toolkit, which they track internally as AcSig. These domains share an identical macOS installation command, payload URL structure, and installer interface, suggesting a coordinated campaign.

The use of Bing's legitimate click-tracking redirects, which employ JavaScript to send visitors to their destination, allowed attackers to make the traffic appear to originate from Bing, further enhancing the campaign's deceptive nature. This "Adception" technique highlights attackers' evolving methods to evade detection and exploit trusted platforms to distribute malware.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
cybersecurity

AI Fuels Cybersecurity Mergers and Acquisitions

The cybersecurity industry is currently undergoing a substantial wave of mergers and acquisitions (M&A), with 117 deals reported in the most recent quarter. A key driver behind this heightened activity appears to be the increasing integration of artificial intelligence (AI) across various sectors, leading to a broader range of companies seeking to acquire cybersecurity capabilities.

cloud

AWS AgentCore security undone by prompt requesting credentials

Researchers have identified a critical vulnerability in Amazon Bedrock AgentCore that could allow an attacker to compromise all agents within an AWS account and region by exploiting insufficient network isolation and overly permissive default IAM roles. The flaw, disclosed by Zenity Labs, centers on an attacker's ability to extract temporary AWS credentials from an agent through a single prompt.

security

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have reported an active credential-theft campaign leveraging GitHub Actions workflows, which has led to the compromise of tens of thousands of repositories. The campaign reportedly exploited two high-profile open-source maintainer accounts to propagate a malicious workflow into over 340 repositories directly. One notable instance involved the account of Takashi Kitao,…

ransomware

Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention

German authorities have arrested a Russian national suspected of being a key figure in the Qilin ransomware group. The individual was initially detained in Japan in May while traveling as a tourist in Osaka, following an arrest warrant issued by Germany in connection with a ransomware incident on German soil.

breach

Hundreds of thousands impacted by data breach at biosensor firm iRhythm

Medical device manufacturer iRhythm has confirmed a data breach affecting at least 360,000 individuals, following a cyberattack that occurred in June. The company, known for its Zio Patch cardiac monitoring device, began issuing breach notifications to regulators and victims across multiple states this week.

security

Leader of vast money mule operation that laundered cybercriminal proceeds pleads guilty

Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, pleaded guilty in U.S. federal court on Thursday to charges related to his leadership of an international money laundering operation known as Your Mule Cashout (YMCO). The organization, active from 2007 to 2014, utilized a network of over 15,000 unwitting money mules across the United States, Germany, Italy, the United Kingdom,…