PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A Google ad that appeared to point to Bing redirected some searchers through Bing’s click-tracking service and a compromised retailer’s website to a fake Claude installer, according to Push Security’s October 9, 2026 report. The final page displayed a legitimate-looking installation instruction, but its Copy button supplied a different command that fetched and ran a script. The attack required a visitor to run the command; the ad and redirect alone did not install malware.
How the October 2026 attack worked
Push Security reported that a sponsored Google result for the search “claude mac” showed bing.com as its visible domain. Clicking it began a chain of redirects:
- A Google ad-click redirect returned an HTTP 302 response.
- Bing’s click-tracking page at
bing.com/ck/areturned HTTP 200 and used JavaScript to forward the visitor. - A compromised retailer’s “about us” page returned another HTTP 302 response.
- The visitor reached a fake Claude download page.
The compromised page checked for a Bing referrer and browser headers. The final page also checked the browser’s referrer and sent direct visitors to a 404 page. These checks helped route selected visitors through the lure while making the destination less obvious to people who opened it directly.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Push called this pattern “Adception,” its descriptive name for a search-engine result appearing inside an ad for another search engine. It is not an established industry classification. Push said it detected the incident in a customer environment; its broader claims about its detection capabilities are the company’s own.
Why the fake installer was dangerous
The page looked like a polished Claude download experience and displayed an installation command that matched Anthropic’s legitimate instruction. But the Copy button placed different text on the clipboard. That hidden command printed a Claude-like message, decoded a concealed address, retrieved a script from attacker-controlled infrastructure, and piped it to the macOS shell.
#1 Best Overall
This is a ClickFix-style attack: the page persuades a person to take the final action—here, copy and run a command. The key warning is that visible text and clipboard contents can differ. A familiar product name, a convincing page, or a sponsored search result does not establish that a command is genuine.
Push’s report does not establish a named threat actor, a confirmed victim count, or whether this particular redirect chain remains active. It also does not show that Bing itself served malware or that Anthropic created the fake page. The report describes abuse of a Bing click-tracking redirect and a compromised site to reach an impersonating page.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →How this differs from other Claude-themed campaigns
Several reports in 2026 described malicious instructions presented as Claude installation help, but the delivery paths and reported payloads differ. The available reporting does not establish that these campaigns shared an operator or infrastructure.
| Report | Delivery path and technique | Reported system and payload | What the visitor was asked to do |
|---|---|---|---|
| Push Security, October 9, 2026 | Google ad, Bing click-tracking redirect, compromised retailer page, then a fake download page with referrer checks. | macOS; the report describes a script fetched and run through a shell, but does not name a confirmed payload family. | Copy and run a command whose clipboard contents differed from the command shown on the page. |
| Bitdefender, March 11, 2026 | Google ads for Claude Code led to a fake documentation page hosted on Squarespace. | Windows instructions used a Windows utility; macOS instructions used an obfuscated shell command to retrieve a Mach-O backdoor. | Follow the page’s installation instructions. Bitdefender said the campaign relied on victims doing so, not on a software flaw. |
| BleepingComputer, February 13, 2026 | Google results led to public Claude artifacts or a Medium page impersonating Apple Support. | macOS; the reported payload was MacSync. | Paste shell commands into Terminal. |
| Malwarebytes, May 12, 2026 | Sponsored Google results appeared to lead to Claude and resolved to shared Claude chats imitating installation or Apple Support instructions. | The report describes a loader followed by a second-stage payload. | Paste a Base64-encoded command into Terminal. |
| CSO Online reporting on TrendAI research, June 18, 2026 | A separate seven-week, six-wave campaign used Google Ads, GitLab Pages, and later Claude shared chats. | The report describes targeting of developer-tool searches; it does not identify a payload in the supplied account. | The reported delivery involved malicious pages and shared chats; the specific victim action is not stated in that account. |
The figures reported for earlier incidents are not confirmed infection counts for the October redirect. BleepingComputer, citing Moonlock researchers, reported at least 15,600 views of a malicious guide and said more than 10,000 users accessed content containing dangerous instructions; views and access do not prove infection. Separately, CSO Online reported more than 2,000 victims for TrendAI’s seven-week campaign. Neither figure should be attributed to the October case.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Is it safe to install Claude from a Google ad?
A search ad is not a reliable way to verify an installer. In the October case, the visible domain and the sequence of redirects concealed the final destination, while the page itself imitated a legitimate download experience. An ad being sponsored—or having passed an advertising review—does not mean its final destination is safe.
Open Anthropic’s official documentation independently rather than following an ad, unfamiliar page, or shared chat. Read the installation instructions there, confirm that any command comes from that source, and do not run a command you do not understand. Never rely on a page’s displayed text alone when a button copies something to the clipboard.
Quick Recap
Best Value
What to do if you already ran a command
- Do not run it again or follow additional instructions from the same page.
- If this is a work device, contact your IT or security team promptly and tell them what happened.
- For a personal device, use a trusted security professional or reputable security software to assess it. A scan can be one layer of response, but it is not a guarantee that a system is clean.
- If you entered passwords or other sensitive information after running the command, change those credentials from a separate, trusted device and review active sessions for the affected accounts.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

