Malvertising: fake Claude installers ride Bing redirects

Share
Malvertising: fake Claude installers ride Bing redirects

Claude's popularity has made it a lure — and today's campaign shows how much trust an ad can borrow. One story, dissected.


Hackers are running a fake Claude download page through Google Ads, and the trick is that the ad's destination looks like a Microsoft domain. Security researchers at Push Security, who dubbed the technique "Adception," found a sponsored Google result targeting people searching for "claude mac" whose click URL was a legitimate Bing search-results redirect — so the ad passes Google's checks pointing at bing.com, then Bing's click-tracking endpoint bounces the visitor through a compromised WordPress site belonging to a South American retailer, and only then to a counterfeit Claude page. Two layers of cloaking sit in between: the WordPress hop checks for a Bing referrer and specific browser headers, and the fake Claude site verifies the visitor arrived from Google or Bing — anyone who opens the URL directly, including most security scanners, gets a 404.

The payload delivery is the part that should worry macOS users most. The fake page shows Anthropic's genuine install command, but its copy button swaps a different command into the clipboard — one that prints a friendly "downloading Claude" message while actually decoding a hidden web address, pulling a data file from an attacker-controlled server, and feeding it straight into the Mac's shell. The victim sees the real Claude URL in their terminal while an entirely different script runs. The final payload is still unknown; Push Security says several domains share the same installer interface, command structure, and payload layout, which it tracks internally as one toolkit.

What makes this more than another malvertising story is the laundering chain: attackers no longer need their own domain to look trustworthy in an ad — they rent credibility from a search engine's redirect instead, and the brand they counterfeit is simply whichever AI tool people are installing this week. It's the same pattern behind the stolen-access trade we covered in September — Hackers are selling stolen Claude and Gemini access at 97% off — where the product being abused is trust in Claude itself.

What to watch: whether Google and Bing close the redirect-as-click-URL hole, and what the recovered payload turns out to be.

Have you seen a "Claude installer" ad that didn't lead where it claimed? Tell us in the comments.

Read more

Akhetonics says its all-optical CPU reaches a customer in 2026

Akhetonics says its all-optical CPU reaches a customer in 2026

Light-based computing keeps promising more than it delivers — but one Munich startup has just put a date on its bet, and the interview laying it out is doing the rounds on Hacker News this week. Akhetonics says it will deploy its first commercial machine with a major customer by the end of 2026, with several more planned for 2027. The company, founded by Michael Kissner and Leonardo Del Bino, is building a computer where data enters as light, is switched as light, and circulates through memory

The Week in AI — October 5–11, 2026

The Week in AI — October 5–11, 2026

Every big claim this week turned out to rest on fine print more interesting than the headline: revenue only the company reporting it can define, safety tests sandboxed while the product keeps the web, and a Pentagon phase-out nobody would confirm until reporters kept asking. The week's top 5 1. OpenAI's revenue was $20 billion below the numbers everyone quoted — and the gap was definitional. The Financial Times reported Thursday that OpenAI's annualized revenue runs roughly $20 billion unde

Drone strike shuts a third Yandex data center, taking YandexGPT offline

Drone strike shuts a third Yandex data center, taking YandexGPT offline

Russia's largest tech company is learning what the AI era's infrastructure war looks like from the receiving end — three data centers in four days, and with them much of the cloud layer Russian businesses run on. A Ukrainian drone strike knocked out Yandex's data center in Vladimir early Sunday morning, the third of the company's facilities hit since October 8. The site — reported at roughly 50 MW and designed for about 2,880 server racks — stopped operating completely after the attack, Yandex

Agent teams cost up to 5x more, barely score higher

Agent teams cost up to 5x more, barely score higher

The multi-agent hype train hit a benchmark this weekend — and the grid and the trucking regulators had quiet weeks of their own. Vals AI put agent teams head-to-head with single agents on its Vibe Code Bench, and the teams cost between 1.8 and 5.1 times more for almost no extra quality. The evals company ran GPT-6 Sol and Claude Opus 5.5 solo and in teams across 50 apps at two reasoning efforts; out of four comparisons, only one was statistically significant — Sol at medium effort, where the t