The latest AcSig ClickFix campaign demonstrates a concerning evolution in how attackers bypass conventional cybersecurity controls. By combining Google Ads, Bing's legitimate redirect infrastructure, a compromised WordPress website and a fake Claude installer, cybercriminals are exploiting the trust associated with established internet platforms.
The attack technique, described by researchers as Adception, is particularly interesting because the malicious destination is concealed behind several legitimate-looking stages. The Bing domain displayed in the advertisement is genuine, and the intermediate website belongs to a legitimate business. Yet the final destination attempts to trick macOS users into executing an attacker-controlled script.
Even more concerning is the manipulation of the clipboard. The installation page displays the legitimate Claude command, but clicking the copy button places a different command into the clipboard. The substituted command decodes an attacker-controlled URL, downloads a remote script and executes it through the system shell.
This highlights why security decisions cannot be based exclusively on the reputation of the first domain a user visits. Attackers increasingly use trusted services as intermediaries, compromised websites as redirectors and encoded commands to conceal malicious activity.
Security architectures must evolve toward contextual inspection of complete redirect chains, malicious content detection, command execution monitoring and continuous threat intelligence. Browser and endpoint controls should also identify suspicious clipboard-driven installation workflows.
A legitimate domain can be part of a malicious attack chain without the domain owner being compromised. Trust must be established through behavior and context, not reputation alone.
Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks. [...]
Source: Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks via Bleeping Computer — published 09 Oct 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.