Attackers use search ads and Bing redirects to push fake Claude install pages
What happened
On October 11, 2026, a Hacker News front-page report said attackers used Google search ads and a legitimate Bing redirect to send people searching for Claude to fake install pages, running a ClickFix attack that tricks macOS users into executing malicious commands. Push Security calls the technique Adception. The chain reportedly runs through compromised WordPress sites and ends at claude-desk-code[.]com. The attackers also hide the payload using referrer and browser checks.
Written by AI from the coverage · updated 59 minutes ago
Coverage
Follow the reports to see the story from different sides.
- Hacker News front pageHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
黑客利用 Google 搜索广告与 Bing 的合法重定向,将搜索 Claude 的用户引向假安装页,诱导 macOS 用户执行恶意命令。Push Security 将该手法称为 Adception,攻击链经过被入侵的 WordPress 网站抵达 claude-desk-code[.]com,并通过来源和浏览器检查隐藏攻击内容。
Heat over time
Not enough continuous observations to draw a trend yet.