Attackers use Google ads to send users to a look-alike Claude page
The page shows the correct install command, but its button puts a different command in the clipboard.
Push Security found a campaign with the name Adception. A Google ad for claude mac shows the Bing domain. The ad goes through a website that an attacker controls. The user then gets a look-alike Claude page with a command for macOS. The page shows the correct command, but the button puts a different command in the clipboard. The last payload is not known.
How the ad works
Push Security found that the ad shows the Bing domain. This makes the ad look safe.
The ad goes through a Google redirect and a Bing endpoint. Then it goes to a WordPress website of a retailer in South America. An attacker controls this website.
How it hides
The campaign uses 2 layers of cloaking to keep scanners out:
- The WordPress website checks for a Bing referrer and some browser headers.
- The look-alike page uses JavaScript to check that the visitor came from Google or Bing.
- A visitor who goes to the page with no ad gets a 404 error page.
The command trick
The page shows the correct command from Anthropic. When the user pushes the button, a different command goes in the clipboard.
This command gets a file from a server that the attacker controls. It then sends the file to the zsh shell. In the terminal, the user sees the correct URL.
What is not known
Push Security does not know the last payload. It found other domains of the same toolkit, with the name AcSig.
This is a brief. We point to the report and do not rewrite it. Read it at the source below.
Sources
- Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksbleepingcomputer.com
Posted