← Blog · · df00tech

Malicious Google Ads Abuse Bing Redirects to Push Fake Claude Installers in ClickFix Campaign

security-news campaign

What Happened

According to BleepingComputer, threat actors are abusing legitimate Bing search-result redirect URLs as the click-through destination in Google search ads. Victims searching for Anthropic's Claude are served malicious ads that route through a trusted Bing redirect before landing on a fake Claude installer page, which delivers a ClickFix-style attack.

ClickFix campaigns typically trick users into copying and pasting attacker-supplied commands (often disguised as a CAPTCHA fix or installer step) into the Windows Run dialog or a terminal, leading to execution of malicious payloads without a traditional file download.

Why It Matters for Defenders

This technique layers two forms of trust abuse: paid placement on a major search engine, and a redirect chain through another legitimate domain (Bing), which can help the malicious ad evade basic URL-reputation filtering and ad-network review. Because the lure impersonates Claude — a widely used AI tool with a large and growing developer/enterprise user base — organizations with staff who self-install AI tools are at risk, particularly in environments without strict software installation controls.

ClickFix-style attacks are notable because they rely on user-executed commands rather than exploiting a vulnerability, so they can bypass controls focused solely on malicious downloads or email attachments.

What Defenders Should Watch For

  • User education: treat any prompt asking users to manually paste a command into Run, PowerShell, or a terminal to "fix" an installer or verification issue as a red flag.
  • Monitor for process creation chains originating from browser processes that spawn powershell.exe, cmd.exe, or mshta.exe shortly after a user interacts with a search ad or redirect.
  • Inspect outbound traffic and referrer chains for search-ad clicks that hop through unrelated legitimate domains (e.g., Bing redirect links appearing inside Google Ads click URLs) before landing on unfamiliar installer domains.
  • Flag AI-tool installer downloads from domains that do not match the vendor's official domain (e.g., anything other than Anthropic's claude.ai or official download pages).
  • Review and tighten software restriction policies or application allowlisting for AI-tool installers on managed endpoints.

Developing Story

This is a net-new, developing report with no associated CVE or confirmed threat-actor attribution at this time; details may evolve as the campaign is further analyzed. For the original reporting, see BleepingComputer's coverage.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.