Malicious Google Ads Abuse Bing Redirects to Push Fake Claude Installers in ClickFix Campaign
What Happened
According to BleepingComputer, threat actors are abusing legitimate Bing search-result redirect URLs as the click-through destination in Google search ads. Victims searching for Anthropic's Claude are served malicious ads that route through a trusted Bing redirect before landing on a fake Claude installer page, which delivers a ClickFix-style attack.
ClickFix campaigns typically trick users into copying and pasting attacker-supplied commands (often disguised as a CAPTCHA fix or installer step) into the Windows Run dialog or a terminal, leading to execution of malicious payloads without a traditional file download.
Why It Matters for Defenders
This technique layers two forms of trust abuse: paid placement on a major search engine, and a redirect chain through another legitimate domain (Bing), which can help the malicious ad evade basic URL-reputation filtering and ad-network review. Because the lure impersonates Claude — a widely used AI tool with a large and growing developer/enterprise user base — organizations with staff who self-install AI tools are at risk, particularly in environments without strict software installation controls.
ClickFix-style attacks are notable because they rely on user-executed commands rather than exploiting a vulnerability, so they can bypass controls focused solely on malicious downloads or email attachments.
What Defenders Should Watch For
- User education: treat any prompt asking users to manually paste a command into Run, PowerShell, or a terminal to "fix" an installer or verification issue as a red flag.
- Monitor for process creation chains originating from browser processes that spawn
powershell.exe,cmd.exe, ormshta.exeshortly after a user interacts with a search ad or redirect. - Inspect outbound traffic and referrer chains for search-ad clicks that hop through unrelated legitimate domains (e.g., Bing redirect links appearing inside Google Ads click URLs) before landing on unfamiliar installer domains.
- Flag AI-tool installer downloads from domains that do not match the vendor's official domain (e.g., anything other than Anthropic's claude.ai or official download pages).
- Review and tighten software restriction policies or application allowlisting for AI-tool installers on managed endpoints.
Developing Story
This is a net-new, developing report with no associated CVE or confirmed threat-actor attribution at this time; details may evolve as the campaign is further analyzed. For the original reporting, see BleepingComputer's coverage.