Fraudulent Google Ads redirect users to fake Claude downloads
Hackers are using Google search ads that redirect through Bing's click-tracking system to lure users seeking Claude for Mac to install malware. They exploit Bing's trusted domain to evade ad security checks and ultimately direct victims to a fake Claude installer site. This page provides a command that looks legitimate but pastes malicious instructions, silently downloading and executing a harmful file on macOS systems.
- Attack uses Google ads with Bing redirects to evade detection
- Compromised WordPress sites forward traffic to a fake Claude page
- Cloaking techniques block direct scans and hide malware
- Fake page gives malicious macOS command for download
- Attack targets users searching for Claude Mac installer
Sources covering this
In this story
More in Cybersecurity
Hackers hijack ccTLDs to forge Google certificates
Attackers gained control of the main domain registries for Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as), allowing them to…
Hackers exploit AhsayCBS flaws to install cryptominers
Attackers are exploiting two unpatched vulnerabilities in the AhsayCBS backup management platform to gain remote access to systems,…
US offers $10M reward for alleged Hafnium hacker Zhang Yu
The US State Department has announced a reward of up to $10 million for information that could help identify or locate Zhang Yu, a…
Red Hat and IBM remediate 400+ Java library vulnerabilities
Red Hat and IBM have addressed over 400 previously unknown vulnerabilities in widely used open source Java libraries, following the…