Attackers are abusing legitimate advertising and search redirect infrastructure - Google search ads whose click URLs are routed through Bing search-result redirect endpoints - to send victims to fake Claude installer pages. The payload is not a novel exploit and there is no CVE in the report. The risk is the delivery chain: trusted ad networks, trusted redirectors, an AI brand users are actively searching for, and a ClickFix social-engineering step that convinces the victim to execute the final command themselves.
This matters for every enterprise with Windows users who browse, search, download AI tools, or have local admin rights. The campaign bypasses many perimeter assumptions because the first visible hops are reputable: googleadservices or Google Ad click surfaces, then Bing redirect URLs such as bing.com/ck/a, then a lookalike Claude download page. The decisive control point is not blocking Claude or Bing wholesale. It is detecting the transition from browser redirect to installer execution and, critically, the ClickFix pattern where Explorer, a browser, or the Run dialog spawns PowerShell, mshta, curl, or similar living-off-the-land tooling.
Treat this as active malvertising and user-assisted execution, not as a vulnerability in Claude, Google, or Bing. No vendor patch fixes a victim pasting an encoded command. The defensive priority is to reduce search-ad trust for software downloads, detect encoded command execution spawned from user shell contexts, and contain endpoints before credential theft or follow-on payload staging begins.
Technical Analysis
Affected products, versions, and platforms
- Primary exposure: Windows endpoints used for interactive browsing and software downloads, especially where users can run PowerShell, mshta.exe, rundll32.exe, curl.exe, or install unsigned desktop applications.
- Abuse surface: Google Ads click URLs, Bing redirect URLs under bing.com/ck/a, fake Claude installer pages, and download infrastructure controlled by the actor.
- Impersonated product: Anthropic Claude desktop/installer branding. This is brand abuse; Claude itself is not reported as compromised.
- Likely objectives in comparable ClickFix campaigns: initial access, infostealer delivery, credential and browser-session theft, and staging for ransomware or hands-on intrusion. Confirm final payloads only from endpoint telemetry in your environment.
CVE and exploitation status
No CVE identifier appears in the source summary, and none should be invented. The technique is active in the wild according to the reporting: legitimate ad clicks and search redirects are being chained to malicious landing pages. The exploitation requirement is user interaction: a searched term, an ad click, a redirect through Bing, a fake installer download, then a ClickFix prompt that instructs the user to run or paste a command.
Defender's view of the attack chain
- Victim searches for Claude download or a similar high-intent term.
- A malicious Google ad appears credible and uses a click URL that includes a Bing redirect path, commonly resembling bing.com/ck/a with encoded parameters.
- The redirect chain ends at an actor-controlled fake Claude page. The page may imitate branding, offer a Windows installer, and use urgency or verification language.
- The victim downloads an installer named to resemble Claude, Claude Desktop, Claude Setup, or similar.
- ClickFix begins: the page or installer claims there is an error, update requirement, CAPTCHA, or verification fix and tells the user to open Run, Terminal, or PowerShell and paste a command.
- The pasted command often launches powershell.exe with -enc, -e, -encodedcommand, FromBase64String, Invoke-Expression, Invoke-WebRequest, DownloadString, curl.exe, mshta.exe, or rundll32.exe. The parent is frequently explorer.exe because the user pressed Win+R or pasted into a shell, but a browser or installer process can also appear upstream.
- The command retrieves a second stage from a remote URL, writes to user-writable paths such as Downloads, AppData, Temp, or ProgramData, and may establish persistence using Run keys, scheduled tasks, or startup folder entries.
The most reliable defensive choke points are: ad/redirect telemetry, fake installer naming and download provenance, user-context spawning of script interpreters, encoded PowerShell, network connections from browsers to Bing redirect URLs immediately followed by connections to unknown domains, and persistence created shortly after a browser download.
Detection & Response
The highest-fidelity behavior is not the ad itself; it is the sequence of browser redirect, fake Claude download, then user-launched encoded execution. Tune aggressively for your environment, but do not ignore Explorer-parent PowerShell simply because administrators occasionally use Win+R.
---
title: ClickFix User Context Spawns Encoded PowerShell
id: 3b9e6c21-7a5d-4b0f-9d3c-8f2a1e4c5b67
status: experimental
description: Detects PowerShell launched from Explorer, Run dialog behavior, browsers, or installer-like processes with encoded or download cradle content consistent with ClickFix prompts.
references:
- https://attack.mitre.org/techniques/T1059/001/
- https://attack.mitre.org/techniques/T1204/002/
author: Security Arsenal
date: 2026/04/24
tags:
- attack.execution
- attack.t1059.001
- attack.t1204.002
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- 'explorer.exe'
- 'chrome.exe'
- 'msedge.exe'
- 'firefox.exe'
- 'brave.exe'
- 'msiexec.exe'
selection_image:
Image|endswith:
- 'powershell.exe'
- 'pwsh.exe'
- 'mshta.exe'
- 'curl.exe'
- 'rundll32.exe'
selection_cli:
CommandLine|contains:
- ' -enc'
- ' -e '
- 'encodedcommand'
- 'frombase64string'
- 'invoke-expression'
- 'iex '
- 'downloadstring'
- 'invoke-webrequest'
- 'iwr '
- 'start-bitstransfer'
condition: selection_parent and selection_image and selection_cli
falsepositives:
- Rare administrator one-liners run from Win+R; baseline helpdesk and admin workstation behavior before enforcing
level: high
---
title: Fake Claude Installer Downloaded and Executed From User Paths
id: 7d1a0f52-4c68-4d79-9a4b-1e6f0a2c9d55
status: experimental
description: Detects execution of files whose names imitate Claude installers from Downloads, Desktop, Temp, or AppData paths shortly after browser download activity.
references:
- https://attack.mitre.org/techniques/T1036/
- https://attack.mitre.org/techniques/T1204/002/
author: Security Arsenal
date: 2026/04/24
tags:
- attack.defense_evasion
- attack.t1036
- attack.execution
logsource:
category: process_creation
product: windows
detection:
selection_name:
Image|contains:
- 'claude'
- 'claude desktop'
- 'claude_setup'
- 'claude-setup'
- 'claudeinstaller'
selection_path:
Image|contains:
- 'Downloads'
- 'Desktop'
- 'AppData'
- 'Temp'
- 'ProgramData'
condition: selection_name and selection_path
falsepositives:
- Legitimate Claude deployments should come from managed software tooling and approved paths; inventory approved package names before rollout
level: medium
---
title: Persistence Created Shortly After Browser Download or ClickFix Execution
id: 2a5f8d90-13b7-4ec4-9f62-7c0b8d1e4a29
status: experimental
description: Detects Run key, scheduled task, or startup persistence command lines created by processes executing from user-writable paths after suspected fake installer activity.
references:
- https://attack.mitre.org/techniques/T1060/
- https://attack.mitre.org/techniques/T1053/005/
author: Security Arsenal
date: 2026/04/24
tags:
- attack.persistence
- attack.t1060
- attack.t1053.005
logsource:
category: process_creation
product: windows
detection:
selection_parent_path:
ParentImage|contains:
- 'Downloads'
- 'AppData'
- 'Temp'
- 'ProgramData'
selection_persist:
CommandLine|contains:
- 'schtasks /create'
- 'reg add'
- 'CurrentVersion\Run'
- 'Startup'
- 'New-ScheduledTask'
- 'Register-ScheduledTask'
condition: selection_parent_path and selection_persist
falsepositives:
- Software updaters and enterprise packaging; scope to non-approved signer paths and correlate with prior browser download events
level: high
// Hunt ClickFix sequence: browser/search redirect exposure, fake Claude process, then user-context encoded execution
let lookback = 7d;
let suspiciousParents = dynamic(['explorer.exe','chrome.exe','msedge.exe','firefox.exe','brave.exe','msiexec.exe']);
let encodedTerms = dynamic([' -enc',' -e ','encodedcommand','frombase64string','invoke-expression','iex ','downloadstring','invoke-webrequest','iwr ','curl.exe','mshta.exe']);
let Proc = materialize(
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| project Timestamp, DeviceId, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, FolderPath, SHA256, ReportId);
let EncodedClickFix = Proc
| where InitiatingProcessFileName in~ (suspiciousParents)
| where FileName in~ ('powershell.exe','pwsh.exe','mshta.exe','curl.exe','rundll32.exe')
| where ProcessCommandLine has_any (encodedTerms);
let FakeClaude = Proc
| where FileName has_any ('claude','setup','installer') or FolderPath has 'claude'
| where FolderPath has_any ('Downloads','Desktop','AppData','Temp','ProgramData');
EncodedClickFix
| join kind=leftouter FakeClaude on DeviceId
| summarize Commands=make_set(ProcessCommandLine), FakeInstallers=make_set(FolderPath1), FirstSeen=min(Timestamp), LastSeen=max(Timestamp) by DeviceName, AccountName, InitiatingProcessFileName, FileName
| order by LastSeen desc;
// Optional network pivot for Bing redirect followed by unknown destinations; enable where browser network events are onboarded
DeviceNetworkEvents
| where Timestamp >= ago(lookback)
| where RemoteUrl has 'bing.com/ck/a' or InitiatingProcessCommandLine has_any ('googleadservices','bing.com/ck/a')
| join kind=inner (DeviceNetworkEvents | where Timestamp >= ago(lookback) | project DeviceId, Timestamp, RemoteUrl, RemoteIP, InitiatingProcessFileName) on DeviceId
| where Timestamp1 between (Timestamp .. Timestamp + 10m)
| where RemoteUrl1 !has_any ('microsoft.com','bing.com','google.com','anthropic.com','claude.ai')
| summarize RedirectCount=count(), Destinations=make_set(RemoteUrl1), IPs=make_set(RemoteIP1) by DeviceName, InitiatingProcessFileName
| order by RedirectCount desc
-- Velociraptor hunt for user-context ClickFix execution and fake Claude installer artifacts
SELECT Pid,
Ppid,
Name,
Exe,
CommandLine,
Username,
CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)(encodedcommand|frombase64string|downloadstring|invoke-expression|invoke-webrequest|start-bitstransfer|mshta|curl.exe|rundll32)'
AND (
CommandLine =~ '(?i)( -enc| -e |iex )'
OR Name =~ '(?i)(powershell|pwsh|mshta|curl|rundll32)'
)
-- Correlate suspicious processes with downloaded Claude-named files in common user staging locations
LET files = SELECT FullPath, Name, Size, Mtime, Ctime
FROM glob(globs=['C:/Users/*/Downloads/*claude*','C:/Users/*/Desktop/*claude*','C:/Users/*/AppData/Local/Temp/*claude*','C:/ProgramData/*claude*'])
WHERE Name =~ '(?i)(claude|setup|installer)'
SELECT * FROM files
# Verify and harden Microsoft Defender controls relevant to malvertising, script abuse, and post-download execution. Run elevated.
$ErrorActionPreference = 'Stop'
# Confirm Defender AV is healthy and real-time plus network/web protection are enabled
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, NISEnabled, OnAccessProtectionEnabled, QuickScanSignatureVersion, AntivirusSignatureLastUpdated
Set-MpPreference -DisableRealtimeMonitoring $false
Set-MpPreference -DisableBehaviorMonitoring $false
Set-MpPreference -DisableIOAVProtection $false
Set-MpPreference -EnableNetworkProtection Enabled
Set-MpPreference -EnableControlledFolderAccess Disabled
# Enable ASR rules most relevant to ClickFix and downloaded-script execution
$asr = @{
'5BEB7EFE-FD9A-4556-801D-275E5FFC04CC' = 'Enabled' # Block execution of potentially obfuscated scripts
'D3E037E1-3EB8-44C8-A917-57927947596D' = 'Enabled' # Block JavaScript/VBScript from launching downloaded executable content
'56A863A9-875E-4185-98A7-B882C64B5CE5' = 'Enabled' # Block abuse of exploited vulnerable signed drivers
'7674BA52-37EB-4A4F-A9A1-F0F9A1619A2C' = 'Enabled' # Block Adobe Reader from creating child processes
'D4F940AB-401B-4EFC-AADC-AD5F3C50688A' = 'Enabled' # Block all Office applications from creating child processes
'26190899-1602-49E8-8B27-EB1D0A1CE869' = 'Enabled' # Block Office communication application from creating child processes
}
foreach ($id in $asr.Keys) { Add-MpPreference -AttackSurfaceReductionRules_Ids $id -AttackSurfaceReductionRules_Actions Enabled }
# Audit PowerShell logging and block policy bypass where practical
Set-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -Name 'EnableScriptBlockLogging' -Value 1 -Force
Set-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -Name 'EnableScriptBlockInvocationLogging' -Value 1 -Force
Set-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ModuleLogging' -Name 'EnableModuleLogging' -Value 1 -Force
Set-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ModuleLogging\ModuleNames' -Name '*' -Value '*' -Force
# Add high-value exclusions monitoring for fake Claude staging paths and remove risky local admin where not approved
$paths = @('C:\Users\*\Downloads','C:\Users\*\Desktop','C:\ProgramData')
foreach ($p in $paths) { Get-MpPreference | Select-Object -ExpandProperty ExclusionPath | Where-Object { $_ -eq $p } }
Get-LocalGroupMember -Group 'Administrators' | Select-Object Name, ObjectClass, PrincipalSource
# Create a rapid containment snapshot for IR triage
$out = "$env:ProgramData\SecurityArsenal\ClickFix-Triage-$(Get-Date -Format yyyyMMdd-HHmmss).txt"
New-Item -ItemType Directory -Path (Split-Path $out) -Force | Out-Null
Get-Process powershell,pwsh,mshta,curl,rundll32 -ErrorAction SilentlyContinue | Select-Object ProcessName,Id,Path,StartTime | Out-File $out -Append
Get-MpThreatDetection | Sort-Object InitialDetectionTime -Descending | Select-Object -First 25 | Out-File $out -Append
Write-Output "Triage snapshot written to $out"
Immediate Response Actions
- Isolate suspected hosts before credential rotation if encoded PowerShell, mshta, curl, rundll32, or a fake Claude installer executed. Preserve memory if the user pasted a command and a second-stage connection is uncertain.
- Capture evidence: browser history and cache, download provenance/zone identifier, Google ad click URL if available, Bing redirect URL, landing domain, installer hash, command line, parent process, clipboard only if already lawfully collected by approved tooling, and persistence locations.
- Reset credentials for the affected user and any sessions present on the host. Prioritize browser cookies, SSO refresh tokens, cached credentials, password managers, and AI service sessions.
- Search backward seven to thirty days for similar Bing redirect sequences, fake Claude names, and Explorer-parent encoded PowerShell. Malvertising waves often reuse ad copy while rotating domains.
- Block confirmed actor domains, hashes, and redirect parameter patterns at DNS, web proxy, email, and EDR. Do not block bing.com/ck/a globally unless your business can tolerate search breakage; instead alert on its combination with software-download intent, Google Ads referrers, and rapid transition to low-reputation domains.
Remediation and Prevention
There is no vendor patch, CVE, or CISA KEV deadline in the source item. Remediation is control hardening and user-risk reduction.
- Enforce a managed software catalog for Claude and other AI tools. Users should never install AI clients from search ads. Publish the exact approved internal path and pin the legitimate vendor domain in communications.
- Deploy browser policies that flag or block downloads from search advertisements for high-risk categories such as AI tools, remote access, VPN clients, password managers, and browser extensions.
- Configure secure web gateway rules to alert when googleadservices or Google ad click flows redirect through bing.com/ck/a and then to newly registered or low-reputation domains within minutes.
- Reduce user execution capability: remove local admin, enable application control for user-writable paths, constrain PowerShell for standard users where operationally feasible, and block or tightly monitor mshta, curl, rundll32, regsvr32, and bitsadmin when launched by Explorer or browsers.
- Turn on PowerShell Script Block Logging, Module Logging, process command-line auditing, Microsoft Defender network protection, SmartScreen, and ASR rules listed above. Validate alerts in audit mode first on developer and admin populations.
- Train users specifically on ClickFix: any page that says press Win+R, paste a command, open Terminal, or fix a CAPTCHA by running code is malicious until proven otherwise. Provide a one-click report path and do not punish fast reporting.
- For procurement and marketing teams: monitor brand impersonation and malicious ads using your company and key vendor names. Report abusive ads to Google and malicious redirects to Microsoft while preserving evidence internally.
Metrics That Prove Control Value
- Percentage of endpoints with command-line auditing, PowerShell logging, network protection, and target ASR rules enabled.
- Mean time from first Bing redirect telemetry to EDR isolate decision.
- Count of Explorer-parent encoded PowerShell events per week and true/false positive ratio after tuning.
- Percentage of AI and developer-tool installs sourced from the managed catalog rather than manual downloads.
- Number of ad-sourced software download blocks by browser policy before execution.
Related Resources
Security Arsenal Red Team Services AlertMonitor Platform Book a SOC Assessment pen-testing Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.