The lure
A legitimate domain was only the first hop
A Google ad that appeared to point to Bing was an unlikely route to a fake software installer. Push Security observed exactly that during a search for Claude on macOS. The sponsored result used Bing's search-result redirect, then sent the browser through a compromised retail website to a fake Claude download page.
The chain matters because each hop can look less suspicious than the destination. The Bing domain was real, and the intermediate retailer was a legitimate website that had been compromised. Push also found checks that changed what visitors saw depending on the referrer and browser context. Visiting the final address directly could produce a different result from following the ad as a user would.
The second deception
The visible command was not the copied command
The fake page displayed Anthropic's legitimate-looking installation command. Its Copy button placed a different command on the clipboard—one that decoded another address, retrieved a script and piped it into the macOS shell. A person comparing the page with the vendor's instructions might believe the command was safe, then paste something else.
Do not invent a payload
Defender workflow
Investigate the journey, not just the landing page
- 1
Preserve the full navigation. Capture the ad click, redirect sequence, referrers and final destination where browser or proxy telemetry allows. A direct visit to the landing domain may miss cloaked behavior.
- 2
Inspect the executed command. Compare what the page displayed with what the user pasted and ran. Look for encoded URLs and a shell fetching and executing remote content.
- 3
Assess the endpoint. If the command ran, preserve terminal history and endpoint evidence, identify the fetched script and any subsequent process or network activity, and contain according to the findings.
- 4
Reduce repeat exposure. Point staff to the vendor's documented download path and teach them to inspect the pasted command before execution, especially when an installer asks for a terminal command.
Defender note
A trusted URL can still be a redirect
“Check the domain” is too narrow for this case. Trusted domains can carry redirect links, and the text next to a Copy button can differ from the clipboard. The useful evidence is the complete path from search result to executed command.