# Fake Claude downloads use Bing redirects to conceal malicious Google ads

_Published Friday, October 9, 2026 at 6:03 PM EDT · Security · Latest · Tier 2 — Notable_

![Fake Claude downloads use Bing redirects to conceal malicious Google ads — Primary](https://www.bleepstatic.com/content/hl-images/2026/05/07/ClaudeChats.png)

Attackers are routing Google search ads through legitimate Bing redirects to send macOS users to fake Claude download pages, security researchers at Push Security found. The campaign uses Bing's trusted domain as the advertised destination, then passes visitors through a compromised retailer's WordPress website.

The fake installer displays Anthropic's legitimate installation command, but its copy button substitutes a command that downloads and executes an attacker-controlled script. Checks for referral information and browser headers hide the malicious page from direct visitors and security scanners. The final payload remains unknown, leaving researchers unable to establish what malware, if any, the script installs.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-bing-redirects-to-push-claude-clickfix-attacks/)

---
Canonical: https://techandbusiness.org/newswire/7-Lb1ScSYIiF_NnBI3_yTO
Published: 2026-10-09T22:03:50.224Z
Story chronology: 2026-10-09T20:31:37.000Z
Retrieved: 2026-10-10T01:05:37.747Z
Publisher: Tech & Business (techandbusiness.org)
