Hackers Abuse Google Ads and Bing Redirects to Push Claude ClickFix Attacks
Hackers use Bing search result redirects in Google ads to trick users into downloading fake Claude installers that deliver ClickFix attacks. The technique appears to evade security checks by using Bing's trusted domain as the ad destination.
Intelligence analysis by Qwen 2.5 (3B)

Hackers exploit Bing's trusted domain in Google ads to redirect users to fake Claude installers, which deliver ClickFix attacks. The technique uses multiple layers of cloaking to prevent security checks and automated analysis.
Hackers trick people into downloading fake software by using a trusted website (Bing) in ads. The fake software tries to trick people into running bad code, but it hides the bad code in a way that makes it hard to see.
Analysis
{"heading_1":"The Adception Technique","paragraph_1":"This attack highlights the risks of trusting domain names in ads and the importance of robust security measures to detect and block malicious redirects. Security teams should be aware of this technique and implement additional layers of security to prevent such attacks.","paragraph_2":"The use of multiple layers of cloaking and the display of legitimate commands in the fake download page make it difficult for security teams to detect the attack. This underscores the need for continuous monitoring and updates to security protocols to stay ahead of evolving attack techniques.","paragraph_3":"To mitigate such attacks, security teams should implement strict domain validation and use of secure ad networks. They should also educate users about the risks of clicking on suspicious links and the importance of using reputable sources for downloading software.","heading_2":"Layers of Cloaking","heading_3":"Implications and Mitigation","paragraph_4":"In addition, security teams should consider using ad blockers and other security tools to prevent malicious redirects and ensure that users are directed to legitimate websites. Regular security audits and updates to security protocols are also crucial to prevent such attacks."}
Key points
- Hackers use Bing's trusted domain in Google ads to redirect users to fake Claude installers.
- The fake software uses multiple layers of cloaking to prevent security checks and automated analysis.
- Security teams should implement strict domain validation and use of secure ad networks to prevent such attacks.
By improving ad validation and security measures, we can prevent such attacks in the future.
If security teams do not update their protocols, hackers may find new ways to trick people into downloading fake software.



