Google Ad Showing bing.com Leads to a Fake Claude Installer

Push Security published an analysis on October 9, 2026 of a Google search ad for "claude mac" that displayed bing.com as its domain and led to a fake Claude download page. It matters to anyone who installs AI tools from search results, and to anyone who runs a WordPress site.

What we know

  • Who is reporting it: Push Security, which sells a browser security tool, in an analysis dated October 9, 2026. It says it detected the attack in a customer environment. This is third-party research, not a notice from Google, Microsoft or Anthropic.
  • The ad: a Google search for "claude mac" returned a sponsored result whose listed domain was bing.com, not a Claude or Anthropic lookalike, according to Push.
  • The chain: four hops, per the analysis: Google's ad-click redirect; Bing's click redirect, the one Bing puts behind its own search results; the "about us" page of a South American homeopathy retailer running a compromised WordPress site; and the fake download page.
  • Why it got through review: Push says Google's ad review approved a destination that was simply another search engine. The company says it had not seen that Bing link used as an ad destination and found no earlier public reporting of it.
  • Two layers of cloaking: the compromised site only redirects when the visit arrives with a Bing referrer and certain browser headers. The fake page only appears to visitors coming from Google or Bing; anyone opening it directly gets a 404 error.
  • The final trick: the page shows Anthropic's real install command, but its Copy button puts a different one on the clipboard. Once pasted, the terminal prints Claude's legitimate address while it downloads and runs a script from another server.
  • Dates: the Bing link carries a timestamp of October 5, 2026, which Push takes as the probable date it was generated.
  • Scope: Push lists eight lure addresses tied to the same kit, which it calls AcSig. It does not say how many people were hit, how the retailer's site was breached or whether Google removed the ad. What the script installs is not known either: BleepingComputer writes that the final payload remains unknown.
  • The wider figure: four in five attacks of this kind that Push detects reach the victim through a search engine. That number comes from its own detections, not from the internet as a whole.

What changes and what doesn't

One habit changes: checking the domain on an ad is no longer enough. Here the visible domain belonged to a well-known search engine. The landing page name does not help either: of the eight addresses on Push's list, only one contains the word "claude", by this article's count.

Copy and paste changes too: what a page displays and what lands on your clipboard can be two different things.

The rest stays the same. This is not a flaw in Claude or at Anthropic: the official command is still the one in its documentation. Malicious ads are not new either; Push presents this as a more elaborate case than most, and one other attackers will probably copy.

There is also a second victim that is easy to miss: the retailer whose site served as the bridge. Its page was real and indexed, and it was still forwarding some of its visitors.

How to tell if it affects you

If you install AI tools (Claude, ChatGPT, Gemini or any other):

  1. Do not download software from a "Sponsored" result. Type the address. Claude's official download is at claude.com/download and the Claude Code install command is at code.claude.com/docs.
  2. Read a command before you paste it into a terminal. Paste it into a text editor first. The official one for macOS is a short line that points to claude.ai. The swapped one in this case, according to Push, starts with `echo`, carries a long string of meaningless letters and ends by sending the download to `zsh`.
  3. If you already pasted a command like that, treat it as an incident: take the machine off the network and change, from another device, the passwords and API keys it held. This is this article's own precaution; Push does not detail what the script does.

If you run a WordPress site:

  1. Test your site the way a search visitor sees it. Search for your brand on Bing and on Google and open several inner pages from the results, the "about us" page included. Do not type the address. If you end up somewhere else, there is a redirect you did not set up. The test is not conclusive: according to Push, the redirect also required certain headers.
  2. Open "Security issues" in Google Search Console. That is where Google flags hacked content it detects on a site.
  3. Ask whoever maintains the site to review server redirects (the `.htaccess` file, for instance) and any plugin nobody remembers installing. The red flag is a rule that depends on where the visit comes from.
  4. Update WordPress, plugins and the theme. Push does not say how that site was breached, so there is no specific plugin to point to.

Related: Fake ChatGPT, Gemini and Claude Ad Portals Target Ad Accounts

Sources

Updates: this note will be extended if Google, Microsoft or Anthropic comment on this campaign, or if Push Security identifies what the script installs.