$ techbeacon▋
Threats

Hackers Exploit Google Ads and Bing Redirects to Distribute Fake Claude Installer

Hackers Exploit Google Ads and Bing Redirects to Distribute Fake Claude Installer

Security researchers have uncovered a new campaign that blends Google search advertisements with Bing's legitimate redirect service to funnel victims toward a counterfeit Claude AI installer that carries the ClickFix malware payload.

The scheme works by embedding a Bing redirect URL as the final click destination in a paid Google ad. When a user clicks the ad, the Google platform hands off the request to the Bing redirect, which then forwards the traffic to a site offering what appears to be an official Claude installer. The installer is, in fact, a trojanized package that drops ClickFix, a remote-access tool used by attackers to gain persistent control of compromised machines.

ClickFix is known for its ability to establish encrypted command-and-control channels, exfiltrate data, and download additional payloads. By masquerading as a popular AI assistant, the malicious installer exploits the current hype around generative AI tools, increasing the likelihood that unsuspecting users will run the file. Once executed, the malware silently installs itself and begins communicating with servers operated by the threat actors.

The abuse of legitimate ad infrastructure is not new, but the combination of two major platforms in a single attack chain raises the difficulty of detection. Google’s ad network has long been a target for malicious actors who embed malicious URLs in ad copy, while Bing’s redirect service is intended to streamline link tracking for advertisers. By chaining the two, the attackers benefit from the trust users place in both brands, as well as the built‑in traffic‑routing capabilities that bypass many standard URL‑filtering solutions.

Experts warn that users who encounter unexpected prompts to download Claude or similar AI software should verify the source before proceeding. Checking the publisher’s digital signature, comparing the download URL against the official provider’s website, and employing reputable anti‑malware tools are recommended safeguards. Organizations are also advised to monitor outbound traffic for connections to known ClickFix command‑and‑control endpoints.

Both Google and Microsoft have acknowledged the report and indicated that they are reviewing the abuse of their services. In past incidents, the companies have taken down offending ads and refined their automated scanning mechanisms. Security firms continue to track the campaign’s evolution, noting that the attackers may shift to other high‑profile software names if the Claude vector loses effectiveness.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related