Claude ClickFix: How to Detect & Block Adception Malvertising

SOC Briefing Summary :: Executive Key Takeaways
- [01]Threat actors deploy an Adception malvertising scheme, using Google Ads and legitimate Bing click-tracking redirects (bing.com/ck/a) to bypass ad security and push fake Claude installers.
- [02]Bypassing ad-screening checks with Bing's domain reputation, the attack funnels users through cloaked WordPress sites to claude-desk-code[.]com, triggering ClickFix clipboard hijacking.
- [03]Victims pasting deceptive terminal install scripts execute Atomic macOS Stealer (AMOS), compromising Keychains and credentials; defenders must restrict clipboard APIs and hunt piped shell execution.
Executive Summary
Threat intelligence analysts have uncovered a sophisticated malvertising framework dubbed "Adception", wherein cybercriminals abuse legitimate Microsoft Bing search-result redirects (`bing.com/ck/a`) inside Google Search Ads to evade automated advertising security reviews and deliver ClickFix social engineering attacks. Documented by researchers at Push Security and disclosed on October 9, 2026, the campaign specifically targets software engineers and artificial intelligence practitioners searching for desktop AI tooling, notably queries such as "claude mac", "claude code", and "claude desktop".
By configuring Google Ads to display and route through trusted bing.com click-tracking URLs, the adversaries exploit the cross-engine domain reputation to bypass perimeter secure web gateways (SWG) and ad-screening algorithms. The redirect bounce routes victims through compromised third-party WordPress platforms utilizing multi-layered traffic filtering (cloaking), ultimately landing users on deceptive lure sites such as claude-desk-code[.]com.
Once on the landing page, the attack transitions into a modern ClickFix scenario: victims attempting to copy an apparent command-line installer (curl -fsSL https://claude.ai/install.sh | bash) have their system clipboards hijacked via malicious JavaScript. When pasted into macOS Terminal, the hidden script deploys the Atomic macOS Stealer (AMOS), systematically siphoning Apple Keychain credentials, browser session cookies, cryptocurrency wallets, and developer SSH keys. This dispatch provides a root-cause forensic breakdown of the Adception redirect architecture, maps adversary tactics to the MITRE ATT&CK matrix, and delivers actionable detection and prevention controls for enterprise security teams.
---
Technical Vulnerability Analysis & Attack Chain
The Adception campaign exploits inherent trust assumptions in modern web security: search engines inherently trust each other's domain reputations, and users inherently trust terminal commands copied from polished software distribution interfaces.

Root-Cause & Exploitation Mechanics
The multi-stage intrusion lifecycle leverages open redirects, cloaking, and DOM clipboard poisoning:
- Adception Cross-Engine Open Redirect Abuse: Rather than registering throwaway ad display URLs that trigger immediate domain reputation scrutiny, the threat actors purchase Google Search ads featuring
bing.comas the display and target domain. The ad URL embeds a Bing click-tracking endpoint (https://www.bing.com/ck/a?!&&p=...&u=a1...). Becausebing.comis an authoritative, high-reputation domain, automated ad verification scanners categorize the link as benign. - Intermediary Compromise & Traffic Filtering (Cloaking): Bing's redirect parameter forwards the victim to an intermediary compromised WordPress website (such as an innocent South American e-commerce shop). This intermediary acts as a defensive cloaking tier:
- It validates the HTTP
Refererheader to ensure the visitor genuinely originated from Bing/Google. - It inspects visitor IP ranges, user-agents, and residential Autonomous System Numbers (ASNs).
- Automated security scanners, web crawlers, and researchers navigating directly to the URL receive HTTP 404 Not Found responses or standard retailer storefront content.
- It validates the HTTP
- Brand Impersonation Landing Page (`claude-desk-code[.]com`): Real target users navigating on macOS or Windows are redirected to
claude-desk-code[.]com. The domain presents a pixel-perfect replica of Anthropic's Claude download portal, featuring authentic typography, brand iconography, and a tailored "Install via Terminal" callout. - ClickFix DOM Clipboard Hijacking: When the victim clicks the visual "Copy Command" button—which displays
curl -fsSL https://claude.ai/install.sh | bash—the page triggers an event listener invoking the browser'snavigator.clipboard.writeText()API. The benign visible string is discarded; instead, an obfuscated Base64-encoded shell command is written into the user's operating system clipboard buffer. - Interactive Shell Execution & AMOS Infiltration: Guided by the on-screen prompts, the user opens macOS Terminal (
/System/Applications/Utilities/Terminal.app) and pressesCmd + Vfollowed byEnter. The pasted command silently executes in the background:- Connects to an external payload delivery server.
- Downloads and mounts a malicious disk image or drops an unsigned Mach-O Mach binary.
- Prompts the user with a spoofed system dialog box requesting the macOS administrative password under the guise of "Claude Helper Tool Installation".
- Drops Atomic macOS Stealer (AMOS) to extract Keychain entries, Safari/Chrome session tokens,
.aws/credentials, and browser passwords to threat actor C2 servers.
---
MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)
| Tactic | Technique ID | Technique Name | Operational Context |
|---|---|---|---|
| Resource Development | T1583.008 | Acquire Infrastructure: Malvertising | Purchasing targeted Google Ads targeting developer keywords ("claude mac"). |
| Initial Access | T1204.001 | User Execution: Malicious Link | Luring developers to click sponsored search engine ads routing via Bing open redirects. |
| Defense Evasion | T1608.004 | Stage Capabilities: Drive-By Target | Abusing bing.com/ck/a open redirect endpoints to evade ad-screening filters. |
| Defense Evasion | T1027 | Obfuscated/Encrypted Information | Obfuscating terminal dropper scripts and hiding payloads behind multi-stage cloaking. |
| Defense Evasion | T1497 | Virtualization/Sandbox Evasion | Inspecting HTTP Referer headers and residential ASNs to serve 404s to analysis sandboxes. |
| Execution | T1204.002 | User Execution: Malicious File/Command | Tricking users into pasting hijacked clipboard scripts into macOS Terminal. |
| Collection | T1115 | Clipboard Data | Overwriting OS clipboard data via JavaScript navigator.clipboard.writeText APIs. |
| Credential Access | T1555.001 | Credentials from Password Stores: Keychain | AMOS stealer querying Apple Keychain databases for stored enterprise credentials. |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | Exfiltrating compressed credential bundles and cloud tokens over encrypted HTTPS C2. |
---
Threat Actor Profile & Campaign Attribution
The Adception operation illustrates the expanding professionalization of infostealer distribution brokers:
- Evolving ClickFix Tactics: The "ClickFix" social engineering methodology was originally popularized in early 2024 by threat actors abusing fake CAPTCHA and Google Chrome "Update Needed" dialogs (such as ClearFake and ChainScript). In Q3 and Q4 2026, adversary groups pivoted away from generic browser update lures toward specialized developer tooling (Anthropic Claude, Cursor, Docker Desktop, and Ollama) where terminal installation via
curl | bashis standard practice. - Malvertising Syndicate Modus Operandi: The use of cross-engine open redirect hopping demonstrates advanced familiarity with Google Ads Policy Enforcement mechanisms. By interposing an authoritative Microsoft Bing click-tracker between Google's ad infrastructure and the compromised intermediary, the threat actors achieve exceptional ad lifespan before account suspension.
- Downstream Monetization: Payloads deployed via this campaign predominantly consist of AMOS (Atomic macOS Stealer) on macOS and Lumma/StealC on Windows endpoints. Harvested developer logs are rapidly routed into Dark Web marketplaces to facilitate downstream cloud environment takeovers.
---
Detection & SOC Mitigation Playbook
1. Concrete Remediation & Workarounds
Enterprise IT and security operations centers must implement multi-layered host and browser defenses:
Step 1: Restrict Unverified Clipboard Write APIs via Browser Group Policies
Enterprise browser administrators can restrict or audit programmatic clipboard access on untrusted web domains using Google Chrome / Microsoft Edge enterprise policies:
// Chrome / Edge Enterprise Management Policy (managed preferences)
{
"DefaultClipboardSetting": 2,
"ClipboardBlockedForUrls": [
"http://*/*",
"https://*/*"
],
"ClipboardAllowedForUrls": [
"https://*.internal.corp",
"https://github.com/*"
]
}Step 2: Implement macOS Terminal Execution Restrictions and Shell Auditing
Deploy endpoint management profiles (Jamf / Intune / Kandji) that enforce auditing on interactive shell sessions executing downloaded payloads:
# macOS Terminal / zsh configuration to warn on execution of unverified piped shell commands
# Inject defensive wrapper into /etc/zshrc to log piped curl/bash invocations
audit_curl_exec() {
if [[ "$1" =~ "curl.*\|.*(bash|sh|zsh)" ]]; then
logger -p security.warning -t DFIR_TERMINAL_AUDIT "Suspicious curl piped to shell detected: $1"
fi
}Step 3: Block Search Engine Open Redirect Parameters on Secure Web Gateways
Configure Secure Web Gateways (Zscaler, Cloudflare One, Palo Alto Prisma) to inspect search engine click-tracking parameters and block requests where the destination parameter (&u=) decodes to external, unverified hosts.
2. Network & Perimeter Defenses
- DNS Perimeter Sinkholing: Block resolution of known ClickFix lure infrastructure (
claude-desk-code[.]com). - Inspection of Malvertising Egress: Monitor corporate proxy logs for user sessions transitioning from Google Ads click identifiers (
gclid) directly into Bing click endpoints (bing.com/ck/a) and subsequently into external untrusted domains.
3. Endpoint Detection & Hunting Query
Validated Sigma Rule (YAML)
title: Suspicious Interactive Terminal Execution from ClickFix Clipboard Lure
id: f184a201-9c42-4b82-9a31-618d7890e142
status: experimental
description: Detects interactive macOS Terminal or shell processes launching curl, osascript, or base64 decoding piped directly into bash/sh, indicative of ClickFix clipboard injection.
author: CyberNewsAI Threat Research Team
date: 2026/10/10
references:
- https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-bing-redirects-to-push-claude-clickfix-attacks/
logsource:
category: process_creation
product: macos
detection:
selection_parent:
ParentImage|endswith:
- '/Terminal'
- '/iTerm'
- '/iTerm2'
selection_commands:
CommandLine|contains:
- 'curl -fsSL'
- 'osascript -e'
- 'base64 -d'
- 'echo'
selection_piped_exec:
CommandLine|contains:
- '| bash'
- '| sh'
- '| zsh'
filter_legitimate_package_managers:
CommandLine|contains:
- 'brew.sh'
- 'nvm.sh'
- 'rustup.rs'
condition: selection_parent and selection_commands and selection_piped_exec and not filter_legitimate_package_managers
falsepositives:
- Legitimate developer environment setups explicitly authorized by IT
level: high
tags:
- attack.execution
- attack.t1059.004
- attack.t1204.002
- attack.t1115Microsoft Sentinel / Defender KQL Hunting Query
// Microsoft Sentinel / Defender for Endpoint: Hunting for macOS AMOS Dropper and ClickFix Script Invocations
// Identifies Terminal and shell processes executing piped network commands
DeviceProcessEvents
| where TimeGenerated >= ago(7d)
| where ActionType == "ProcessCreated"
| where InitiatingProcessFileName in~ ("Terminal", "iTerm", "iTerm2", "zsh", "bash")
| where ProcessCommandLine has_any ("curl", "wget", "osascript") and ProcessCommandLine has_any ("| bash", "| sh", "| zsh")
| where not(ProcessCommandLine has_any ("brew.sh", "sdkman.io", "nvm.sh"))
| project TimeGenerated, DeviceName, DeviceId, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, FolderPath
| summarize Count = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by DeviceName, AccountName, ProcessCommandLine
| order by Count descSplunk Hunting Query (SPL)
index=* sourcetype IN ("macos:process", "osquery:process", "pan:endpoint")
| where (match(parent_process_name, "(?i)(Terminal|iTerm)") OR match(process_name, "(?i)(bash|zsh|sh)"))
| where match(process_cmd, "(?i)(curl.*\|.*(bash|sh|zsh)|osascript.*display dialog.*password|claude.*install)")
| stats count values(process_cmd) as executed_commands values(user) as users by host, parent_process_name
| eval alert_type="HIGH: Suspected ClickFix Terminal Dropper Execution"
| sort - count---
| Indicator Type | Value / Pattern | Operational Context |
|---|---|---|
| Malicious Lure Domain | claude-desk-code[.]com | Impersonated Anthropic Claude desktop installer delivering ClickFix payloads. |
| Abused Redirect Service | bing[.]com/ck/a?* | Legitimate Microsoft Bing search click-tracking endpoint abused in Google Ads. |
| Compromised Infrastructure | Compromised Third-Party WordPress Sites | Cloaking intermediaries filtering out bots and directing targets to lure pages. |
| Final Payload (macOS) | Atomic macOS Stealer (AMOS) | In-memory and script-based credential stealer siphoning Apple Keychains and cookies. |
| Attack Technique | ClickFix Clipboard Overwrite | Social engineering vector abusing JavaScript navigator.clipboard.writeText. |
| Target Keywords | claude mac, claude code, claude desktop | Targeted Google Search ad queries poisoned by threat actors. |
claude-desk-code[.]combing[.]com/ck/a?*Compromised Third-Party WordPress SitesAtomic macOS Stealer (AMOS)ClickFix Clipboard Hijacking via navigator.clipboard.writeTextclaude mac / claude code / claude desktop// VERIFIED_SOURCES_&_REFERENCES
Watch Full Video Briefings on YouTube
Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.
Related Threat Intelligence
View Archive
Ploutus-D Malware: How to Detect & Block ATM Jackpotting Attacks
Fugitive architect of Ploutus-D ATM malware captured. Discover how cartels exploit Kalignite XFS middleware and how banks can secure physical cash dispensers.

FakeGit: How to Detect & Block 17,000+ Malicious GitHub Repos
FakeGit campaign weaponizes 17,610 GitHub repositories to deploy SmartLoader and StealC malware. Learn how to detect lures, hunt IOCs, and secure credentials.

Warlock Ransomware Hits Water and Telecom via SharePoint Flaws
China-linked Warlock ransomware breaches water and telecom operators via SharePoint flaws, deploying BYOVD EDR-killers and VS Code tunnels to strike 40 hosts.