Executive Summary
In October 2026, cybercriminals launched a sophisticated malvertising campaign dubbed 'Adception' targeting macOS users searching for Claude AI software. The attackers exploited Google Ads and Bing's click-tracking redirects to bypass security measures, directing victims through compromised WordPress sites to fake Claude download pages. The campaign used multi-layered cloaking and clipboard hijacking techniques, substituting legitimate installation commands with malicious Base64-encoded scripts that downloaded unknown payloads from attacker-controlled servers.
This incident highlights the evolving sophistication of AI-themed social engineering attacks and the exploitation of trusted advertising platforms. As AI tools become mainstream business applications, attackers increasingly target these popular services to deliver malware while exploiting user trust in legitimate domains and installation processes.
Why This Matters Now
AI adoption is accelerating across enterprises, making AI-themed attacks a critical threat vector. The sophisticated use of trusted advertising platforms and clipboard hijacking represents an evolution in malvertising that bypasses traditional security controls.
Attack Path Analysis
Attackers used Google Ads with legitimate Bing redirects to deliver ClickFix attacks through compromised websites, tricking users into executing malicious terminal commands disguised as legitimate Claude AI installer instructions. The attack leveraged multiple cloaking layers and clipboard manipulation to bypass security controls and deliver unknown payloads to macOS systems.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers created malicious Google Ads targeting 'claude mac' searches, using legitimate bing.com domains in ad URLs to appear trustworthy. Users clicked ads thinking they were accessing official Claude installer.
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Acquire Infrastructure: Domains
Drive-by Compromise
Obfuscated Files or Information
User Execution: Malicious File
Command and Scripting Interpreter: Unix Shell
Deobfuscate/Decode Files or Information
Masquerading: Match Legitimate Name or Location
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Testing
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.16
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Secure Application Development
Control ID: Application Security
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Secure Development Policy
Control ID: A.14.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Marketing/Advertising/Sales
Malvertising attacks exploiting Google Ads and Bing redirects create significant trust erosion and platform security risks for advertising operations and campaigns.
Computer Software/Engineering
ClickFix attacks targeting AI tools like Claude pose severe risks through fake installers, malicious terminal commands, and compromised development environments.
Information Technology/IT
Multi-layer cloaking techniques and compromised WordPress sites require enhanced egress filtering, anomaly detection, and zero trust segmentation for protection.
Financial Services
Encrypted traffic inspection and strict compliance controls essential to prevent malvertising campaigns from compromising sensitive financial data and systems.
Sources
- Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attackshttps://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-bing-redirects-to-push-claude-clickfix-attacks/Verified
- Adception: Malvertising + Another Search Engine's Search Resultshttp://pushsecurity.com/blog/adception-malvertising-another-search-engines-search-resultsVerified
- Custom ChatGPTs push ClickFix attacks to deploy RAT malwarehttps://www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/Verified
- New Infinity Stealer malware grabs macOS data via ClickFix lureshttps://www.bleepingcomputer.com/news/security/new-infinity-stealer-malware-grabs-macos-data-via-clickfix-lures/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this ClickFix campaign by constraining lateral movement and controlling egress communications. Post-compromise activity scope would be significantly limited through microsegmentation and identity-aware access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial browser compromise would likely still occur, but subsequent payload execution scope would be constrained by workload isolation and identity-scoped network access policies.
Control: Zero Trust Segmentation
Mitigation: Privilege escalation attempts would likely face restricted network access boundaries, limiting the attacker's ability to reach privileged services or administrative interfaces across network segments.
Control: East-West Traffic Security
Mitigation: Lateral movement scope would likely be significantly constrained by identity-aware traffic inspection and microsegmentation, limiting attacker reachability to adjacent systems and sensitive workloads.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely face enhanced visibility and behavioral analysis, potentially constraining the attacker's ability to maintain persistent communication channels across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be constrained by controlled egress policies and traffic inspection, limiting the volume and types of data that could be transmitted to external destinations.
While initial endpoint compromise may occur, the overall organizational impact would likely be significantly reduced through network isolation and controlled access boundaries limiting attack propagation.
Impact at a Glance
Affected Business Functions
- Data Security and Privacy
- System Administration
- Employee Productivity
- Brand Reputation Management
Estimated downtime: 2 days
Estimated loss: $25,000
Potential compromise of macOS systems through malicious shell script execution, including access to user credentials, browser sessions, system files, and sensitive corporate data stored on infected endpoints. Unknown final payload makes full scope uncertain.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Cloud Firewall (ACF) with URL filtering to block malicious redirects and enforce egress controls preventing unauthorized downloads from suspicious domains
- • Implement Inline IPS (Suricata) to detect and block known ClickFix attack signatures and malicious payload delivery attempts
- • Enable Cloud Native Security Fabric (CNSF) for real-time inspection and autonomous blocking of deceptive AI-related malvertising campaigns
- • Configure Egress Security & Policy Enforcement to prevent unauthorized outbound connections to attacker-controlled domains like lake-90[.]com
- • Establish Multicloud Visibility & Control to detect anomalous user interactions with suspicious installation prompts and clipboard manipulation attempts



