Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
Hackers use Google Ads and Bing redirects to deliver fake Claude installers that run ClickFix commands.
Push Security reported hackers using Google ads whose destinations are legitimate Bing click-tracking URLs, which then redirect through a compromised South American retailer’s WordPress site to claude-desk-code[.]com. The fake macOS Claude page displays Anthropic’s real install command, but the copy button substitutes a Base64-decoded curl that fetches a script from lake-90[.]com and pipes it into zsh. Referrer and header cloaking sends direct visitors and scanners to a 404. The final payload is unknown; Push tracks the shared ClickFix toolkit as AcSig.
73