Hackers Are Using Google Ads to Spread Fake Claude Installers — Here's How

·
Listen to this article~5 min

Hackers are hijacking Bing redirects in Google Ads to push fake Claude installers that deliver ClickFix attacks. Here's how to spot the trap before you click.

You know that feeling when you click a search ad, thinking you're heading to a trusted site, but something feels a little off? That's exactly what hackers are counting on right now. They're hijacking legitimate Bing redirects and using them as click URLs in Google search ads, all to push fake Claude installers that deliver something called a ClickFix attack. And honestly? It's sneaky enough to fool even careful users. ### What Exactly Is a ClickFix Attack? ClickFix isn't your typical malware download. Instead of exploiting a software bug, it tricks *you* into running the malicious code yourself. The fake installer page shows a fake error message or a "fix" prompt, and then asks you to copy a command and paste it into your terminal or Run dialog. The moment you do that, you're essentially inviting the attacker in. They can steal credentials, install backdoors, or drop ransomware. It's social engineering at its finest — and it works because it feels like you're solving a problem, not creating one. ### Why Bing Redirects Make This So Dangerous Here's where it gets clever. Hackers are using real Bing search-result redirect URLs as the click-through links in Google Ads. That means when you hover over the ad, you see a legitimate microsoft.com or bing.com address. It looks safe. It feels safe. But that redirect takes you straight to a malicious page hosting the fake Claude installer. Google's ad review systems often miss it because the destination URL itself isn't obviously malicious — it's a redirect chain that only reveals its true destination after you click. > "The most dangerous attacks don't break down the door. They hand you the key and ask you to unlock it yourself." ### Who's Being Targeted? Right now, the campaign seems focused on people searching for AI tools — especially Claude, the AI assistant from Anthropic. If you're a developer, a marketer, or just someone curious about AI, you're in the crosshairs. The ads often appear at the top of search results, which makes them even more convincing. - Developers looking for Claude's desktop app - Small business owners exploring AI tools - Privacy-conscious users searching for antidetect browsers and similar software - Anyone who types "download Claude" into Google ### How to Spot a Fake Installer Before It's Too Late A few simple habits can keep you safe: - Never copy and paste commands from a website into your terminal unless you fully understand what they do. - Type the official URL yourself instead of clicking ads. For Claude, go directly to anthropic.com. - Check the final destination of any redirect. You can use a URL expander tool to see where it really goes. - Keep your antidetect browser or regular browser updated — many now flag suspicious redirect chains. - If a download page asks you to "fix" something by running a command, close the tab. That's the attack. ### Why This Matters for Antidetect Browser Users If you're using an antidetect browser to manage multiple profiles, you're already thinking about privacy and security. But this attack bypasses a lot of that. It doesn't rely on browser fingerprinting or tracking — it relies on you trusting a search ad. That's why it's so important to treat every ad, even ones that look legitimate, with a healthy dose of skepticism. ### The Bottom Line Hackers are getting better at hiding in plain sight. They're using trusted platforms like Google and Bing to lend credibility to their attacks. The ClickFix campaign is a reminder that the weakest link in security is often our own trust — and that's exactly what they're exploiting. Stay curious, stay cautious, and always double-check before you click. Your future self will thank you.