Hackers Abuse Google Ads and Bing Redirects to Deliver Claude ClickFix Attacks
Malicious search ads redirect users to fake Claude installers, exploiting ClickFix social engineering to execute malicious PowerShell commands

Key Takeaways
- Threat actors are abusing Google Ads by using legitimate Bing search-result redirects as click-through URLs.
- Users searching for Claude AI software are being directed to fake installer pages.
- ClickFix social engineering is used to trick victims into executing malicious PowerShell commands.
- The malware payloads delivered can include credential theft, data exfiltration, and ransomware.
Related Security News

FBI Arrests Suspected ShinyHunters Member Following Agency System Breach
The FBI arrested a suspect believed to be a member of the ShinyHunters extortion group, who is alleged to be involved in a recent breach of FBI systems. Director Kash Patel confirmed the arrest on Friday, marking a continued law enforcement effort to disrupt the group's operations.

Unpatched AhsayCBS Vulnerabilities Exploited in the Wild to Deploy Webshells and Cryptominers
Threat actors are exploiting two unpatched vulnerabilities in the AhsayCBS backup management platform. One vulnerability is rated critical severity and another medium severity. The exploitation has been observed in the wild and is being used to deploy webshells for persistent access and cryptocurrency miners for monetization. No patches are currently available, and the vulnerabilities remain unpatched. Affected organizations using AhsayCBS for backup management are at risk of persistent compromise and resource misuse.



