Full Report
Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks. [...]
Analysis Summary
# Tool/Technique: Adception (Bing Redirect to ClickFix)
## Overview
**Adception** is a sophisticated malvertising technique that abuses legitimate Bing search-result redirects (`bing.com/ck/a`) within Google Search Ads. The purpose is to bypass automated ad-security scanners by using a trusted domain as the visible URL. The attack chain leads victims through compromised sites to a fake "Claude" (AI) download page, where a "ClickFix" social engineering tactic is used to trick users into executing malicious commands in their terminal.
## Technical Details
- **Type:** Technique / Social Engineering Framework (ClickFix/AcSig)
- **Platform:** macOS (Primary target in this campaign)
- **Capabilities:** Traffic cloaking, clipboard hijacking, remote script execution (RCE) via terminal piping.
- **First Seen:** October 2024 (Reported)
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- [T1589.002 - Gather Victim Network Information: Search Engines]
- [T1204.001 - User Execution: Malicious Link]
- **[TA0002 - Execution]**
- [T1059.004 - Command and Scripting Interpreter: Unix Shell]
- [T1204.002 - User Execution: Malicious File/Command]
- **[TA0005 - Defense Evasion]**
- [T1564 - Hide Artifacts]
- [T1027 - Obfuscated Files or Information]
- [T1132 - Data Encoding (Base64)]
## Functionality
### Core Capabilities
- **Open Redirect Abuse:** Exploits Bing’s click-tracking (`/ck/a`) to forward users to a malicious destination while appearing as a legitimate `bing.com` link.
- **Multi-Layer Cloaking:**
- **Referrer Checking:** The intermediate compromised site only redirects if the traffic originates from Bing.
- **Environment Validation:** The final landing page uses JavaScript to ensure the visitor came from a search engine; direct hits receive a 404 error.
- **Clipboard Hijacking:** When a user clicks a "Copy" button for a perceived legitimate command, the site replaces the clipboard content with a malicious Base64-encoded string.
### Advanced Features
- **Visual Deception:** The landing page displays legitimate commands (e.g., `curl -fsSL https://claude.ai/install.sh`) to the user, while the actual copied command executes a silent download from an attacker-controlled server.
- **AcSig/ClickFix Toolkit:** Uses a standardized macOS installer interface designed to mimic professional software setup processes.
## Indicators of Compromise
- **File Names:** `*.dat` (Payloads delivered via `curl`)
- **Network Indicators (Defanged):**
- `claude-desk-code[.]com` (Malicious landing page)
- `lake-90[.]com` (Payload delivery server)
- `bing[.]com/ck/a` (Abused redirector)
- **Behavioral Indicators:**
- `zsh` or `bash` execution via a pipe from `curl`.
- Terminal history containing `echo` commands followed by `base64 -d`.
- Unexpected outbound network connections from Terminal/Zsh to non-standard domains.
## Associated Threat Actors
- **AcSig/ClickFix Operators:** The specific group is currently categorized by the toolkit used (ClickFix/AcSig).
## Detection Methods
- **Behavioral Detection:** Monitor for "Curl to Shell" patterns, especially those involving `base64 --decode` or piping directly into `/bin/zsh` or `/bin/bash`.
- **EDR/Endpoint Monitoring:** Alert on processes where the parent is a terminal emulator and the command line includes suspicious downloads of `.dat` or `.sh` files from unknown domains.
- **Network Inspection:** Block or flag traffic to newly registered domains (NRDs) that mimic AI tools (e.g., Claude, ChatGPT).
## Mitigation Strategies
- **User Training:** Educate users on the risks of "Copy-Paste" commands from unofficial websites into the Terminal.
- **Browser Protection:** Use browser security extensions that block known malicious redirects and track reputation.
- **Content Security Policy (CSP):** For organizations, implement strict controls on what scripts can be executed and restrict the use of the `clipboard-write` permission where possible.
- **Endpoint Hardening:** Disable or restrict the ability for standard users to run unassigned scripts downloaded via `curl`.
## Related Tools/Techniques
- **ClickFix:** A broader category of social engineering where users are told to "fix" a browser or installer error by running a provided command.
- **Malvertising:** The use of online advertising to spread malware.
- **Samba/ClearFake:** Other social engineering campaigns utilizing fake browser updates.