A campaign pushing fake Claude installers is combining two tricks that are individually mundane but nasty together: ad clicks laundered through legitimate Bing search redirects, and a "paste this command" prompt that convinces victims to execute the malware themselves. BleepingComputer first detailed the attacks in July 2025, and the underlying technique remains one of the hardest for defenders to catch, because the payload never runs until the user runs it.

The simplest defence comes first: type the official URL yourself. If you want Claude, go directly to Anthropic's site rather than clicking anything — including, especially, a sponsored result. No genuine installer will ever ask you to open the Windows Run dialog and paste a command. If a download page does, close the tab.

How the chain works

The acquisition channel is Google search ads. When a user clicks, the ad's destination is not a malicious host — it is a genuine Bing search-result redirect, which carries a Microsoft-owned domain. That borrowed reputation helps the click slip through ad-review systems that would flag an unknown landing page outright, and it survives the split-second glance a user gives the link before clicking.

The visitor lands on a page dressed up as the official Claude download. Claude's rapid adoption has made it a useful lure precisely because many would-be users have not yet seen the real download page and cannot tell the difference.

The payload itself arrives via the ClickFix technique. Instead of a suspicious executable, the page shows a fake error or verification message and instructs the user to open the Run dialog, paste in a command, and press Enter. It is framed as routine troubleshooting — and it works, because the victim believes they are fixing a broken install.

Why defenders keep losing this one

There is no uninvited exploit to intercept and no downloaded binary for tooling to profile. The malware executes because a person typed it in, voluntarily. Endpoint controls tuned to catch traditional droppers may never fire, and the command runs with the user's own permissions and apparent intent.

That is why the layered trust matters. Google Ads supplies the reach, Microsoft's redirect infrastructure supplies the credibility, and the user supplies the execution. Each control in that chain, examined alone, sees nothing wrong.

What to tell your team

Anyone in an IT team who habitually searches for a tool like "Claude" and clicks the first result — a common enough pattern in fast-moving teams — is exactly the audience this campaign is built for. That habit is now a risk in itself.

For individuals, the guidance is short: download software only from the vendor's own domain, type that domain directly rather than following a link, and treat ad-sponsored results for popular software as untrusted by default. For IT teams, the message to reinforce is the same one, phrased from the other side — no legitimate installer needs you in the Run dialog.

With AI assistants now among the most-searched software categories, expect more brand-abuse lures of this kind. The wrappers will change; the core deception is decades old. Convince the victim to run the payload themselves, and every technical control downstream becomes optional.


一場推廣假冒 Claude 安裝程式的攻擊行動,結合了兩種單獨來看平淡無奇、但同時使用便十分陰險的手法:透過合法 Bing 搜尋重新導向「洗白」的廣告點擊,以及一個「請貼上此指令」的提示,說服受害者親自執行惡意軟件。BleepingComputer 於 2025 年 7 月首次詳細報導有關攻擊,而其核心技術至今仍是防禦者最難應付的手法之一,因為惡意負載(payload)在用戶親自執行之前,根本不會運行。

最簡單的防禦應先行一步:親自輸入官方網址。 如果你想使用 Claude,請直接前往 Anthropic 的網站,而非點擊任何連結——尤其是贊助搜尋結果。真正的安裝程式絕對不會要求你開啟 Windows「執行」對話框並貼上指令。如果下載頁面這樣做,請立即關閉該分頁。

攻擊鏈條如何運作

獲取渠道是 Google 搜尋廣告。當用戶點擊廣告時,廣告的目標並非惡意主機,而是一個真正的 Bing 搜尋結果重新導向,由 Microsoft 擁有的域名承載。這種借來的信譽有助於點擊繞過廣告審核系統——否則一個陌生的連結頁(landing page)會被直接標記——同時亦能逃過用戶點擊前匆匆一瞥連結的檢查。

訪客最終到達一個偽裝成 Claude 官方下載頁的網站。Claude 的迅速普及令它成為極具吸引力的誘餌,正因許多潛在用戶尚未見過真正的下載頁,無法分辨真偽。

惡意負載本身透過 ClickFix 技術投放。頁面並非顯示可疑的可執行檔案,而是展示一個虛構的錯誤訊息或驗證訊息,指示用戶開啟「執行」對話框、貼上指令並按 Enter。整個過程被包裝成例行的故障排除程序——而且屢屢奏效,因為受害者相信自己正在修復一個安裝失敗的程式。

為何防禦者一再失守

當中沒有可攔截的不請自來漏洞利用(exploit),亦沒有可供安全工具分析的已下載二進位檔案。惡意軟件之所以執行,是因為有人自願親自輸入指令。專門針對傳統 dropper 調校的端點防護可能永遠不會觸發,而該指令是以用戶本人的權限,以及看似出於自願的意圖運行的。

正因如此,層層疊加的信任至關重要。Google Ads 提供覆蓋範圍,Microsoft 的重新導向基建提供可信度,而用戶則提供執行。該鏈條中任何一個環節單獨審視,都看不到任何不妥。

應告知團隊的要點

任何 IT 團隊成員如果習慣搜尋「Claude」一類工具並點擊第一個搜尋結果——這在節奏急速的團隊中是相當常見的模式——正是此類攻擊行動鎖定的目標受眾。這個習慣本身已構成風險。

對個人而言,指引簡明扼要:只從軟件供應商本身的域名下載軟件,親自輸入該域名而非跟隨連結,並將熱門軟件的廣告贊助結果預設視為不可信。對 IT 團隊而言,需要強調的信息如出一轍,只是從另一面表述——沒有任何正當的安裝程式需要你開啟「執行」對話框。

隨著 AI 助手已成為搜尋量最高的軟件類別之一,預期將出現更多此類品牌冒充誘餌。外層包裝會不斷轉變;但核心騙局已有數十年歷史。只要說服受害者親自執行惡意負載,下游的一切技術防禦便形同虛設。

新聞來源 / Original News Source