Claude ClickFix: How to Detect & Block Adception Malvertising

•By CyberNewsAI Threat Research Team•VERIFIED INTEL
Adception malvertising campaign abusing Google Ads and Bing redirects to deploy Claude ClickFix attacks

SOC Briefing Summary :: Executive Key Takeaways

  • [01]Threat actors deploy an Adception malvertising scheme, using Google Ads and legitimate Bing click-tracking redirects (bing.com/ck/a) to bypass ad security and push fake Claude installers.
  • [02]Bypassing ad-screening checks with Bing's domain reputation, the attack funnels users through cloaked WordPress sites to claude-desk-code[.]com, triggering ClickFix clipboard hijacking.
  • [03]Victims pasting deceptive terminal install scripts execute Atomic macOS Stealer (AMOS), compromising Keychains and credentials; defenders must restrict clipboard APIs and hunt piped shell execution.
SHARE INTEL:Reddit

Executive Summary

Threat intelligence analysts have uncovered a sophisticated malvertising framework dubbed "Adception", wherein cybercriminals abuse legitimate Microsoft Bing search-result redirects (`bing.com/ck/a`) inside Google Search Ads to evade automated advertising security reviews and deliver ClickFix social engineering attacks. Documented by researchers at Push Security and disclosed on October 9, 2026, the campaign specifically targets software engineers and artificial intelligence practitioners searching for desktop AI tooling, notably queries such as "claude mac", "claude code", and "claude desktop".

By configuring Google Ads to display and route through trusted bing.com click-tracking URLs, the adversaries exploit the cross-engine domain reputation to bypass perimeter secure web gateways (SWG) and ad-screening algorithms. The redirect bounce routes victims through compromised third-party WordPress platforms utilizing multi-layered traffic filtering (cloaking), ultimately landing users on deceptive lure sites such as claude-desk-code[.]com.

Once on the landing page, the attack transitions into a modern ClickFix scenario: victims attempting to copy an apparent command-line installer (curl -fsSL https://claude.ai/install.sh | bash) have their system clipboards hijacked via malicious JavaScript. When pasted into macOS Terminal, the hidden script deploys the Atomic macOS Stealer (AMOS), systematically siphoning Apple Keychain credentials, browser session cookies, cryptocurrency wallets, and developer SSH keys. This dispatch provides a root-cause forensic breakdown of the Adception redirect architecture, maps adversary tactics to the MITRE ATT&CK matrix, and delivers actionable detection and prevention controls for enterprise security teams.

---

Technical Vulnerability Analysis & Attack Chain

The Adception campaign exploits inherent trust assumptions in modern web security: search engines inherently trust each other's domain reputations, and users inherently trust terminal commands copied from polished software distribution interfaces.

Attack Chain Flow
// Attack Chain Flow

Root-Cause & Exploitation Mechanics

The multi-stage intrusion lifecycle leverages open redirects, cloaking, and DOM clipboard poisoning:

  • Adception Cross-Engine Open Redirect Abuse: Rather than registering throwaway ad display URLs that trigger immediate domain reputation scrutiny, the threat actors purchase Google Search ads featuring bing.com as the display and target domain. The ad URL embeds a Bing click-tracking endpoint (https://www.bing.com/ck/a?!&&p=...&u=a1...). Because bing.com is an authoritative, high-reputation domain, automated ad verification scanners categorize the link as benign.
  • Intermediary Compromise & Traffic Filtering (Cloaking): Bing's redirect parameter forwards the victim to an intermediary compromised WordPress website (such as an innocent South American e-commerce shop). This intermediary acts as a defensive cloaking tier:
    • It validates the HTTP Referer header to ensure the visitor genuinely originated from Bing/Google.
    • It inspects visitor IP ranges, user-agents, and residential Autonomous System Numbers (ASNs).
    • Automated security scanners, web crawlers, and researchers navigating directly to the URL receive HTTP 404 Not Found responses or standard retailer storefront content.
  • Brand Impersonation Landing Page (`claude-desk-code[.]com`): Real target users navigating on macOS or Windows are redirected to claude-desk-code[.]com. The domain presents a pixel-perfect replica of Anthropic's Claude download portal, featuring authentic typography, brand iconography, and a tailored "Install via Terminal" callout.
  • ClickFix DOM Clipboard Hijacking: When the victim clicks the visual "Copy Command" button—which displays curl -fsSL https://claude.ai/install.sh | bash—the page triggers an event listener invoking the browser's navigator.clipboard.writeText() API. The benign visible string is discarded; instead, an obfuscated Base64-encoded shell command is written into the user's operating system clipboard buffer.
  • Interactive Shell Execution & AMOS Infiltration: Guided by the on-screen prompts, the user opens macOS Terminal (/System/Applications/Utilities/Terminal.app) and presses Cmd + V followed by Enter. The pasted command silently executes in the background:
    • Connects to an external payload delivery server.
    • Downloads and mounts a malicious disk image or drops an unsigned Mach-O Mach binary.
    • Prompts the user with a spoofed system dialog box requesting the macOS administrative password under the guise of "Claude Helper Tool Installation".
    • Drops Atomic macOS Stealer (AMOS) to extract Keychain entries, Safari/Chrome session tokens, .aws/credentials, and browser passwords to threat actor C2 servers.

---

MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)

MITRE ATT&CK • OPERATIONAL TTP MAPPING
TacticTechnique IDTechnique NameOperational Context
Resource DevelopmentT1583.008Acquire Infrastructure: MalvertisingPurchasing targeted Google Ads targeting developer keywords ("claude mac").
Initial AccessT1204.001User Execution: Malicious LinkLuring developers to click sponsored search engine ads routing via Bing open redirects.
Defense EvasionT1608.004Stage Capabilities: Drive-By TargetAbusing bing.com/ck/a open redirect endpoints to evade ad-screening filters.
Defense EvasionT1027Obfuscated/Encrypted InformationObfuscating terminal dropper scripts and hiding payloads behind multi-stage cloaking.
Defense EvasionT1497Virtualization/Sandbox EvasionInspecting HTTP Referer headers and residential ASNs to serve 404s to analysis sandboxes.
ExecutionT1204.002User Execution: Malicious File/CommandTricking users into pasting hijacked clipboard scripts into macOS Terminal.
CollectionT1115Clipboard DataOverwriting OS clipboard data via JavaScript navigator.clipboard.writeText APIs.
Credential AccessT1555.001Credentials from Password Stores: KeychainAMOS stealer querying Apple Keychain databases for stored enterprise credentials.
ExfiltrationT1041Exfiltration Over C2 ChannelExfiltrating compressed credential bundles and cloud tokens over encrypted HTTPS C2.

---

Threat Actor Profile & Campaign Attribution

The Adception operation illustrates the expanding professionalization of infostealer distribution brokers:

  • Evolving ClickFix Tactics: The "ClickFix" social engineering methodology was originally popularized in early 2024 by threat actors abusing fake CAPTCHA and Google Chrome "Update Needed" dialogs (such as ClearFake and ChainScript). In Q3 and Q4 2026, adversary groups pivoted away from generic browser update lures toward specialized developer tooling (Anthropic Claude, Cursor, Docker Desktop, and Ollama) where terminal installation via curl | bash is standard practice.
  • Malvertising Syndicate Modus Operandi: The use of cross-engine open redirect hopping demonstrates advanced familiarity with Google Ads Policy Enforcement mechanisms. By interposing an authoritative Microsoft Bing click-tracker between Google's ad infrastructure and the compromised intermediary, the threat actors achieve exceptional ad lifespan before account suspension.
  • Downstream Monetization: Payloads deployed via this campaign predominantly consist of AMOS (Atomic macOS Stealer) on macOS and Lumma/StealC on Windows endpoints. Harvested developer logs are rapidly routed into Dark Web marketplaces to facilitate downstream cloud environment takeovers.

---

Detection & SOC Mitigation Playbook

1. Concrete Remediation & Workarounds

Enterprise IT and security operations centers must implement multi-layered host and browser defenses:

Step 1: Restrict Unverified Clipboard Write APIs via Browser Group Policies

Enterprise browser administrators can restrict or audit programmatic clipboard access on untrusted web domains using Google Chrome / Microsoft Edge enterprise policies:

QUERY / DETECTION_RULE
JSON
// Chrome / Edge Enterprise Management Policy (managed preferences)
{
  "DefaultClipboardSetting": 2,
  "ClipboardBlockedForUrls": [
    "http://*/*",
    "https://*/*"
  ],
  "ClipboardAllowedForUrls": [
    "https://*.internal.corp",
    "https://github.com/*"
  ]
}

Step 2: Implement macOS Terminal Execution Restrictions and Shell Auditing

Deploy endpoint management profiles (Jamf / Intune / Kandji) that enforce auditing on interactive shell sessions executing downloaded payloads:

QUERY / DETECTION_RULE
BASH / CLI
# macOS Terminal / zsh configuration to warn on execution of unverified piped shell commands
# Inject defensive wrapper into /etc/zshrc to log piped curl/bash invocations
audit_curl_exec() {
    if [[ "$1" =~ "curl.*\|.*(bash|sh|zsh)" ]]; then
        logger -p security.warning -t DFIR_TERMINAL_AUDIT "Suspicious curl piped to shell detected: $1"
    fi
}

Step 3: Block Search Engine Open Redirect Parameters on Secure Web Gateways

Configure Secure Web Gateways (Zscaler, Cloudflare One, Palo Alto Prisma) to inspect search engine click-tracking parameters and block requests where the destination parameter (&u=) decodes to external, unverified hosts.

2. Network & Perimeter Defenses

  • DNS Perimeter Sinkholing: Block resolution of known ClickFix lure infrastructure (claude-desk-code[.]com).
  • Inspection of Malvertising Egress: Monitor corporate proxy logs for user sessions transitioning from Google Ads click identifiers (gclid) directly into Bing click endpoints (bing.com/ck/a) and subsequently into external untrusted domains.

3. Endpoint Detection & Hunting Query

Validated Sigma Rule (YAML)

QUERY / DETECTION_RULE
SIGMA / YAML
title: Suspicious Interactive Terminal Execution from ClickFix Clipboard Lure
id: f184a201-9c42-4b82-9a31-618d7890e142
status: experimental
description: Detects interactive macOS Terminal or shell processes launching curl, osascript, or base64 decoding piped directly into bash/sh, indicative of ClickFix clipboard injection.
author: CyberNewsAI Threat Research Team
date: 2026/10/10
references:
  - https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-bing-redirects-to-push-claude-clickfix-attacks/
logsource:
  category: process_creation
  product: macos
detection:
  selection_parent:
    ParentImage|endswith:
      - '/Terminal'
      - '/iTerm'
      - '/iTerm2'
  selection_commands:
    CommandLine|contains:
      - 'curl -fsSL'
      - 'osascript -e'
      - 'base64 -d'
      - 'echo'
  selection_piped_exec:
    CommandLine|contains:
      - '| bash'
      - '| sh'
      - '| zsh'
  filter_legitimate_package_managers:
    CommandLine|contains:
      - 'brew.sh'
      - 'nvm.sh'
      - 'rustup.rs'
  condition: selection_parent and selection_commands and selection_piped_exec and not filter_legitimate_package_managers
falsepositives:
  - Legitimate developer environment setups explicitly authorized by IT
level: high
tags:
  - attack.execution
  - attack.t1059.004
  - attack.t1204.002
  - attack.t1115

Microsoft Sentinel / Defender KQL Hunting Query

QUERY / DETECTION_RULE
SENTINEL / KQL
// Microsoft Sentinel / Defender for Endpoint: Hunting for macOS AMOS Dropper and ClickFix Script Invocations
// Identifies Terminal and shell processes executing piped network commands
DeviceProcessEvents
| where TimeGenerated >= ago(7d)
| where ActionType == "ProcessCreated"
| where InitiatingProcessFileName in~ ("Terminal", "iTerm", "iTerm2", "zsh", "bash")
| where ProcessCommandLine has_any ("curl", "wget", "osascript") and ProcessCommandLine has_any ("| bash", "| sh", "| zsh")
| where not(ProcessCommandLine has_any ("brew.sh", "sdkman.io", "nvm.sh"))
| project TimeGenerated, DeviceName, DeviceId, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, FolderPath
| summarize Count = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by DeviceName, AccountName, ProcessCommandLine
| order by Count desc

Splunk Hunting Query (SPL)

QUERY / DETECTION_RULE
SPLUNK / SPL
index=* sourcetype IN ("macos:process", "osquery:process", "pan:endpoint")
| where (match(parent_process_name, "(?i)(Terminal|iTerm)") OR match(process_name, "(?i)(bash|zsh|sh)"))
| where match(process_cmd, "(?i)(curl.*\|.*(bash|sh|zsh)|osascript.*display dialog.*password|claude.*install)")
| stats count values(process_cmd) as executed_commands values(user) as users by host, parent_process_name
| eval alert_type="HIGH: Suspected ClickFix Terminal Dropper Execution"
| sort - count

---

Indicator TypeValue / PatternOperational Context
Malicious Lure Domainclaude-desk-code[.]comImpersonated Anthropic Claude desktop installer delivering ClickFix payloads.
Abused Redirect Servicebing[.]com/ck/a?*Legitimate Microsoft Bing search click-tracking endpoint abused in Google Ads.
Compromised InfrastructureCompromised Third-Party WordPress SitesCloaking intermediaries filtering out bots and directing targets to lure pages.
Final Payload (macOS)Atomic macOS Stealer (AMOS)In-memory and script-based credential stealer siphoning Apple Keychains and cookies.
Attack TechniqueClickFix Clipboard OverwriteSocial engineering vector abusing JavaScript navigator.clipboard.writeText.
Target Keywordsclaude mac, claude code, claude desktopTargeted Google Search ad queries poisoned by threat actors.
Indicators of Compromise (IOCs)
6 Identified
Malicious Lure Domainclaude-desk-code[.]com
Abused Open Redirectbing[.]com/ck/a?*
Intermediary CompromiseCompromised Third-Party WordPress Sites
Final Payload (macOS)Atomic macOS Stealer (AMOS)
Attack VectorClickFix Clipboard Hijacking via navigator.clipboard.writeText
Target Keywordclaude mac / claude code / claude desktop
SHARE INTEL:Reddit
OPERATIONS_BROADCAST

Watch Full Video Briefings on YouTube

Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.

SUBSCRIBE_ON_YOUTUBE