Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads, according to a report from BleepingComputer. The malicious ads direct users to fake Claude installers that deliver ClickFix attacks, a social-engineering technique that can lead to malware execution.
By embedding Bing's redirect URLs in Google Ads, the attackers make their ads appear more trustworthy and potentially bypass some ad filters. The fake installer then triggers the ClickFix payload, which typically relies on tricking users into copying and running malicious code.
This campaign highlights how attackers are increasingly leveraging trusted services to evade detection. Users searching for AI tools like Claude should be cautious about clicking ads and verify the legitimacy of download pages before proceeding.