Fake Claude download uses search adverts and a misleading copy button
Research published: 9 October 2026
Activity date: Observed before publication; one link appears to have been generated on 5 October
Push Security has described a malicious advert shown for a search about Claude on a Mac. The sponsored result appeared to lead to Bing, a familiar search engine. A click passed through Bing’s normal result redirect, then a compromised retailer’s website, before arriving at a fake Claude download page. The researchers call the layered redirect technique “Adception”.
The final page offered an installation command. More troublingly, its Copy button placed a different command on the clipboard from the one displayed on screen. Pasting and running it would fetch a script from an attacker-controlled address. This is a *ClickFix* style trap: the attacker relies on the person to run the harmful command themselves, often after making it look like a routine setup step.
Push observed this chain in a customer environment. Its report does not establish how many people clicked the advert or installed anything. The immediate risk is to Mac users looking for the application, particularly staff who routinely install work tools. Malware installed this way could threaten accounts or business data, although the public report does not prove that every visitor lost information.
Open a software maker’s website directly from a known address, and treat sponsored results as adverts rather than endorsements. Before running any Terminal command from a webpage, compare the pasted text with the official instructions. If you have run the suspicious command, stop using that Mac for sensitive work and ask your IT or security provider to investigate it.






Comments