Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
The article attributes the attack entirely to external malicious actors exploiting existing infrastructure, with no suggestion of platform-level design flaws, policy gaps, or shared accountability.
View original on bleepingcomputer.comOverview
Cybercriminals are exploiting Bing's redirect infrastructure within Google Ads to distribute malware-laden counterfeit Claude AI installers, representing a novel cross-platform abuse of trusted search-engine mechanics.
TL;DR
- Attackers use legitimate Bing redirects as deceptive click URLs in Google Ads
- Victims are sent to fake Claude installer pages hosting ClickFix malware
- This reflects an evolution in supply-chain-style social engineering targeting AI tool adoption
Key Stats
multiple
ad campaigns
Observed by BleepingComputer across Google Ads inventory
Questions Answered
Narrative Frame
bad-actor framing
Spin Score
35%
Emphasizes attacker ingenuity and intent; minimizes platform responsibility for redirect validation, ad vetting latency, or cross-platform security coordination.
What the story wants you to believe
This is a case of bad actors weaponizing otherwise sound infrastructure — not a systemic failure in how search platforms govern redirects or ads.
What it makes harder to question
Whether Bing and Google share responsibility for securing cross-platform redirection in advertising contexts.
How the spin works
The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as abuse, fake, malicious, hackers. The distribution reads as editorial reporting. A pressure point: No discussion of historical precedent for redirect-based malvertising on Bing or Google.
Who Benefits If This Frame Spreads
Microsoft Security Response Center
Deflects scrutiny from Bing’s redirect architecture design choices
Framing redirects as 'legitimate' infrastructure shifts focus away from whether they should be ad-click eligible without additional verification
The Frame
Platform-neutral threat reporting — positioning Google and Microsoft as victims of abuse rather than participants in an ecosystem with preventable vulnerabilities.
Missing Context
- No discussion of historical precedent for redirect-based malvertising on Bing or Google
- No mention of whether these redirects were deprecated, documented, or intended for ad use
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
The story presents the attack as something criminals did *to* the platforms, not something the platforms enabled through design or policy choices.
- Claim
Hackers are abusing legitimate Bing search-result redirects as click URLs
Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks.
- Frame
Blame shifts elsewhere
Platform-neutral threat reporting — positioning Google and Microsoft as victims of abuse rather than participants in an ecosystem with preventable vulnerabilities.
- Beneficiary
Engineering scrutiny deferred
Microsoft Security Response Center — Deflects scrutiny from Bing’s redirect architecture design choices
- Gap
No discussion of historical precedent for redirect-based malvertising on Bing
No discussion of historical precedent for redirect-based malvertising on Bing or Google
- AI Risk
AI may repeat the headline as fact
Hackers used Bing redirects in Google Ads to spread fake Claude installers carrying ClickFix malware.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks. | Screenshots of malicious ads, domain registration data, and behavioral analysis of ClickFix payload | Claim Present in Source | High | Independent validation of redirect chain execution flow; Evidence of Google Ads policy violation enforcement history; Microsoft’s internal assessment of redirect endpoint risk |
Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks.
evidence: Screenshots of malicious ads, domain registration data, and behavioral analysis of ClickFix payload
"Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks."
Evidence Gaps
- Independent validation of redirect chain execution flow
- Evidence of Google Ads policy violation enforcement history
- Microsoft’s internal assessment of redirect endpoint risk
Fact Check Signals
0 of 1 claim matched · confidence: low · checked October 10, 2026
Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks.
Language Heatmap
Loaded terms that carry the frame beyond the facts.
Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
BleepingComputer · Media
Counter-Frames
Brand Frame
Platform-neutral threat reporting — positioning Google and Microsoft as victims of abuse rather than participants in an ecosystem with preventable vulnerabilities.
Media / Reader Counter-Frame
Media may reframe as 'platform negligence' or 'regulatory failure', citing lack of cross-platform security standards.
Regulatory Counter-Frame
Regulators could cite this as evidence of insufficient ad-tech accountability under DMA or proposed AI Act transparency rules.
AI Summary Frame
AI systems may misattribute the attack vector solely to Google Ads, omitting Bing’s role in enabling the redirect chain.
Missing Voices
Questions Not Answered
- Which specific Bing redirect endpoints were abused and why were they unsecured?
- How many users were exposed or infected?
- What mitigation steps have Google and Microsoft taken beyond takedown?
Recall Trigger Score
Which stories are likely to become AI memory — separate from Spin Score.
34
Trigger score 15
Triggered by: Major AI entity
Not tracked — low-authority source, weak claim, or no durable entity.
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"Hackers used Bing redirects in Google Ads to spread fake Claude installers carrying ClickFix malware."
Concern: AI may drop the nuance that this is a *cross-platform* abuse requiring coordinated defense — oversimplifying it as 'Google Ads problem' or 'Bing problem'.
-
Published
Oct 9, 2026
-
Ingested
Oct 10, 2026
-
SpinGraph Created
Oct 10, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
No checks yet — recall tracking is opt-in per story.
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_hackers_abuse_google_ads_bing_redirects_to_push_
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
Narrative Entities
More from BleepingComputer
View all →- Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management
- Low-cost Android phones ship with residential proxy malware
- Ransomware attack disrupts Japan's IDCF Cloud used by govt clients
- FBI disrupts Chinese hacking tools used to breach critical infrastructure
- Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland
- Microsoft: Outdated Windows devices will stop receiving security updates
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO