Hackers Hijack Bing Redirects to Spread Claude ClickFix Attacks

·
Listen to this article~4 min

Hackers are using Bing redirects in Google Ads to push fake Claude installers that deliver ClickFix attacks. Learn how to protect yourself.

You know that sinking feeling when you click a search ad, expecting one thing, and get something completely different? That's exactly what's happening right now with a sneaky new attack targeting people looking for Claude, the AI assistant. And it's a reminder that even the most trusted platforms can become unwitting accomplices. ### How the Attack Works Hackers are exploiting a loophole in Google Ads and Bing's search results. They're using legitimate Bing redirect URLs as the click-through link in Google search ads. So when you click on an ad that looks like it's promoting Claude, you're actually redirected through Bing to a fake installer page. That page then delivers a ClickFix attack—a technique that tricks you into running malicious commands on your own computer. It's like someone using your friend's trusted voice to convince you to open a suspicious package. The redirect makes the ad appear more legitimate, bypassing some of Google's automated checks. ### What Is ClickFix and Why Should You Care? ClickFix isn't your average malware. Instead of exploiting a software vulnerability, it manipulates you. The fake installer page might show a fake error message or a CAPTCHA, instructing you to copy and paste a command into your terminal or run a script. Once you do, the attackers gain access to your system. This is particularly dangerous because it relies on social engineering rather than technical flaws. Even tech-savvy users can fall for it if they're in a hurry or trust the source. ### Who's Behind This and Who's at Risk? While the exact actors remain unclear, this campaign seems designed to target users interested in AI tools. If you're a developer, researcher, or just someone curious about Claude, you could be a target. The attackers are betting on the popularity of AI assistants to lure victims. ### How to Protect Yourself - **Don't trust ads blindly.** Even if an ad appears at the top of search results, it can be malicious. Always verify the destination URL before clicking. - **Hover over links.** Check where a link really goes. If it's a redirect through Bing or another service, be suspicious. - **Download software only from official sources.** If you want Claude, go directly to Anthropic's website. Don't rely on search ads. - **Never copy-paste commands from a website.** Legitimate installers won't ask you to run scripts in your terminal. - **Use an antidetect browser.** Tools like antidetect browsers can help mask your digital fingerprint and reduce the risk of targeted attacks, but they're not a silver bullet. Combine them with good security habits. ### The Bigger Picture This attack highlights a growing trend: hackers are getting better at abusing legitimate infrastructure. They're not breaking in; they're tricking the system into letting them in. As AI tools become more popular, expect more of these creative attacks. > "The most dangerous attacks are the ones that make you click willingly," says Robert Moore, Lead Antidetect Browser Specialist. "Always pause and think before you click, especially when it comes to installing software." ### What Can Be Done? Google and Microsoft are constantly updating their detection systems, but attackers are always one step ahead. As a user, your best defense is awareness. Stay informed, question everything, and don't let urgency override caution. If you think you've been targeted, run a full antivirus scan and consider changing your passwords. And remember, if something feels off, it probably is.