A clever malvertising scheme is abusing Google Ads and Microsoft Bing redirect endpoints to push malicious terminal scripts to Mac users looking for Anthropic's Claude AI.
Security firm Push Security discovered the campaign after spotting a sponsored Google search result for queries like "claude mac." Instead of sending victims straight to a suspicious domain that ad scanners might flag immediately, the ad displayed the genuine bing.com address. Clicking it triggered a chain reaction: Google sent the user to Bing's click-tracking system, which forwarded the traffic to a compromised South American retailer's WordPress website, which finally delivered the visitor to an impersonation page hosted at claude-desk-code[.]com.
Push Security calls the redirection trick "Adception." By slipping a legitimate Microsoft domain into a Google ad slot, the attackers managed to slip past ad verification checks that normally catch outright fake download portals.
Cloaked Links and Swapped Commands
The trap relied on aggressive filtering to keep security analysts and automated crawlers out. The compromised intermediate site inspected browser headers and verified that the visitor came from Bing. Meanwhile, the fake Claude destination ran JavaScript to verify the person originated from a major search engine. Anyone trying to open the target web address directly received an empty 404 error page.
Those who made it through saw a clean replica of Anthropic's desktop setup page for macOS. It advised users to install the tool by copying a command into Terminal, visibly showing Anthropic's genuine web setup string.
Clicking the page's copy button did something else entirely.
Instead of copying the clean text displayed on screen, the site quietly loaded malicious instructions onto the macOS clipboard. When pasted into the Terminal, the command printed a reassuring message claiming to pull data from official servers. In the background, it decoded an obfuscated web address, fetched an unauthorized file from an external server, and piped the code straight into the Z shell for execution.
Push Security notes that the final payload delivered by the setup script remains unconfirmed. The firm tracks the underlying toolkit as AcSig, noting it has powered multiple fake software domains using the same setup text, web layout, and payload structure.
For Mac owners searching for developer utilities or artificial intelligence desktop apps, the attack highlights an increasingly dangerous delivery method. Clicking copy buttons on web pages bypasses standard browser file-download warnings, and pasting untrusted clipboard snippets directly into Terminal gives unknown scripts immediate access to the system. Anyone installing Claude or related AI coding tools should stick to Anthropic's official site directly, and verify any clipboard text in a plain text editor before running it in a shell.
SDFiled by The Software Desk
Apps, platforms, operating system releases, security fixes and the features arriving in them.
More from this desk →
Be the first to comment
Join the argument. No password, just your email or a passkey.