A Google ad showing a Bing address sent searchers to a fake Claude installer
On October 9, 2026, Push Security published a malvertising technique it nicknamed "Adception". A sponsored Google result for "claude mac" listed bing.com as its domain, and anyone who clicked was passed through a hijacked retail website to a counterfeit Claude download page. What the attack ultimately installs is still unknown.
The ad looked familiar, the destination did not
The research, written by Luke Jennings of Push Security, went live on October 9, 2026, and BleepingComputer covered it the same day. Push says it spotted the attack inside a customer environment. It starts with an ordinary query: someone searching Google for "claude mac" saw a sponsored listing whose domain was plain bing.com, not an Anthropic lookalike. BleepingComputer notes that showing a trusted Bing address instead of an attacker-owned one makes the ad look less suspicious and is meant to slip past ad security checks. Push adds that Google's ad review approved an ad whose destination was simply another search engine.
A click then moved the browser through four hops. First came Google's ad-click redirect, then bing.com/ck/a, the endpoint Bing uses to log clicks on its own results pages. The third hop was the hijacked "about us" page of a genuine homeopathy retailer in South America, and the fourth was the fake Claude download site at claude-desk-code[.]com. According to Push, the attacker took a real, indexed Bing result for the page they had compromised and made it the target of the Google ad. A timestamp inside the Bing link decodes to October 5, 2026, which Push believes is probably when Bing generated it.
Two layers of cloaking and a swapped clipboard command
The chain filters out unwanted visitors with two separate gates. Both sources say the compromised site runs WordPress. That site only forwards visitors whose request carries a Bing referrer plus specific browser headers. The fake Claude page then uses JavaScript to confirm the visitor came from Google or Bing, and anyone opening the address directly lands on a 404 page. BleepingComputer points out that this setup keeps automated scanners from easily inspecting the attack. Push concludes the real target is Google Search users rather than Bing users.
The final page is a polished fake of the Claude download page that suggests a one-line Terminal install for macOS. It displays Anthropic's genuine install command, yet the copy button puts a different command on the clipboard. That command prints a message claiming to fetch Claude from the official site while quietly pulling a file from lake-90[.]com and running it in the macOS zsh shell. Push stresses that the victim sees a legitimate Claude address both on the page and in the terminal. BleepingComputer reports that the final malware delivered is still unknown. Push links several domains sharing the same macOS command and install dialog to a single ClickFix toolkit that it calls AcSig internally.
A familiar domain is no longer proof on its own
Push ranks search ads among the main attack channels it observes: "Search engine malvertising is one of the top delivery vectors we see in the wild." By its own count, 4 in 5 of the ClickFix attacks it detects, InstallFix and LLMshare variants included, reach victims through search engines. Push says this attacker put in more effort than most cases it sees, and expects that if the trick helps campaigns stay off Google's radar, more attackers may adopt similarly cheap steps.
Businesses can take two lessons from this. First, a recognisable domain under an ad says nothing reliable about where the click will end up. Staff who want to install AI tools should skip the ads and go straight to the vendor's official website. Second, one link in the chain was the hijacked site of a legitimate retailer. A compromised site can end up carrying attacks against people its owner has never met, not just against its own visitors.
The sources do not mention Türkiye, so this section is UNALSOFT's view
Neither source mentions Türkiye. They do not say in which countries the ad ran, how many people clicked or were affected, how long the ad stayed live, or whether users in Türkiye were targeted. No response from Google, Microsoft or Anthropic is reported either. The recommendations below are therefore UNALSOFT's interpretation, not facts from the sources.
The same logic applies to teams in Türkiye who find AI tools through search engines. Practical steps: download tools only from the vendor's own domain and bookmark that address; do not treat the domain shown on a sponsored result as sufficient proof; never assume that a command taken with a web page's copy button matches what the page displays, and do not paste a command of uncertain origin into a terminal at all; if a suspicious command was run, disconnect the device from the network and alert the IT team. For site owners, keeping WordPress core and plugins up to date and watching for unexpected redirects comes first. We previously covered how hijacked WordPress sites are kept compromised in our piece on the SC malware documented by Sucuri.
UNALSOFT's take
From an advertiser's point of view, this case shows that a fake sponsored result can be shown to people searching for a brand or product name. Regularly checking which ads customers see when they search for your brand, reporting impersonating ads to the platform and publishing your official download and contact addresses clearly on your site are simple steps that reduce that risk. That is why, in our ad management work, we treat monitoring brand queries as its own step. Because the sources carry no data about Türkiye, this article makes no local impact estimate.
Which ads do people see when they search for your brand?
A short call is enough to review the sponsored results on your brand queries alongside your site's security posture.