BREACH WATCH BRIEF High 🐛 Threat intel

Hackers Exploit Google Ads and Bing Redirects in “Adception” Campaign to Deliver Malicious Claude Installer (ClickFix)

Researchers uncovered a malvertising campaign that uses Google Search ads and Bing click‑tracking redirects to serve a fake Claude macOS installer. The technique bypasses ad‑network security checks, underscoring the need for continuous vendor‑risk monitoring and auditable redirect logging.

SeverityHigh
Type🐛 Threat intel
ConfidenceHigh
ReportedOct 9, 2026
Other / Unknown Advertising platforms (Google Ads, Bing) Publishers and websites that rely on third‑party ad networks macOS end‑users Malware Supply Chain Attack
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.

What happened

Push Security discovered that attackers embed Bing.com click‑tracking URLs in Google Search ads. When a user clicks the ad, Google’s redirect forwards the request to Bing’s tracking endpoint, which then redirects to a compromised WordPress site. That site forwards the visitor to a counterfeit Claude download page that replaces the legitimate install command with a malicious payload, ultimately downloading additional code from an attacker‑controlled server.

Why it matters for trust and compliance

  • This campaign illustrates a gap in third‑party risk oversight: trusted advertising services can be weaponized, so organizations must continuously monitor and evidence vendor‑provided redirect behavior to satisfy audit requirements.
  • Continuous monitoring of ad‑network traffic provides real‑time evidence of third‑party redirection anomalies.
  • Documented redirect logs support audit trails and demonstrate due diligence in supply‑chain risk management.

Who is affected

Advertising platforms (Google Ads, Bing) Publishers and websites that rely on third‑party ad networks macOS end‑users

Recommended actions

  1. Integrate ad‑network redirect data into your vendor‑risk monitoring solution.
  2. Enforce logging of all third‑party redirect chains and regularly review for unexpected domains.
  3. Apply DNS or web‑gateway filtering to block non‑whitelisted destinations originating from ad clicks.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.