Malvertising Threats: How Fake Google Ads Are Being Used to Deliver Malware

Summary:

A recent malware campaign has been identified that exploits the popularity of Anthropic's Claude Code by using malicious Google-sponsored advertisements to redirect users to a counterfeit documentation website. The attackers leverage the ClickFix social engineering technique to persuade users to execute malicious PowerShell or terminal commands, resulting in the installation of credential-stealing malware on Windows systems and a remote access backdoor on macOS devices. Rather than exploiting software vulnerabilities, the campaign relies on user trust in search advertisements and legitimate-looking documentation. Organizations should reinforce user awareness, verify software download sources, restrict the execution of unauthorized scripts and system utilities, and implement endpoint security controls that detect and block such threats.

Technical Description:

The attack begins with a malicious Google Ads campaign that impersonates Claude Code, directing users searching for the software to a counterfeit documentation page hosted on a legitimate Squarespace subdomain. The fake site closely replicates the appearance and content of the official Claude documentation, making it difficult for users to distinguish it from the legitimate resource. Based on the visitor's operating system, the page presents tailored installation instructions that leverage the ClickFix social engineering technique, instructing users to manually execute malicious PowerShell, Command Prompt, or terminal commands under the guise of installing Claude Code.

On Windows systems, the provided command abuses the legitimate mshta.exe utility to retrieve and execute a multi-stage malware payload, ultimately deploying credential-stealing malware detected as Trojan.Stealer.GJ, Trojan.Stealer.GK, IL:Trojan.MSILZilla.245316, and Gen:Variant.Barys.509034. On macOS, the attack uses obfuscated shell commands to decode Base64-encoded content, download a Mach-O binary, and execute a backdoor that can spawn remote shell sessions via/bin/bash or /bin/zsh, enabling attacker-controlled remote command execution. The malware employs multiple layers of obfuscation, anti-analysis techniques, and staged payload delivery to evade detection while establishing persistent remote access to compromised systems. The details and technicalities of the attack campaign are discussed further below.

Delivery and Infection Chain:

The attack is delivered through a malvertising campaign that abuses Google Ads to impersonate the legitimate Claude Code documentation website. Users searching for terms such as "download Claude Code" are presented with a sponsored advertisement that redirects them to a counterfeit documentation page hosted on a trusted Squarespace subdomain. The website closely mimics the official Claude documentation, including its branding, layout, and installation instructions, increasing the likelihood that users will trust the content. Rather than exploiting software vulnerabilities, the attackers rely entirely on social engineering, convincing users to manually execute malicious commands under the pretext of installing the software.

The infection chain was identified as follows:

  • The victim searches for Claude Code using Google Search and clicks a malicious sponsored advertisement that redirects them to a counterfeit documentation website closely resembling the legitimate Claude Code documentation.
  • The fake website identifies the victim's operating system (Windows or macOS) and displays platform-specific installation instructions, prompting the user to execute malicious PowerShell, Command Prompt, or terminal commands using the ClickFix social engineering technique.
  • Once the command is executed, the system downloads and launches a first-stage payload. On Windows, mshta.exe retrieves and executes a malicious HTA file, while on macOS, an obfuscated shell command decodes and executes a secondary script.
  • The second-stage payload downloads and executes the final malware from attacker-controlled infrastructure. Windows systems receive a multi-stage information-stealing malware payload, while macOS systems download and execute a Mach-O backdoor after modifying file attributes and execution permissions.
  • The malware establishes its malicious functionality by stealing sensitive information (Windows) or providing attackers with persistent remote command execution capabilities (macOS), enabling further compromise, credential theft, data exfiltration, and the deployment of additional malicious payloads.

Technical Capabilities:

The malware demonstrates several advanced capabilities designed to facilitate compromise and evade detection. On Windows, it employs mshta.exe as a Living-off-the-Land Binary (LOLBin) to bypass traditional security controls while executing multi-stage payloads that decrypt embedded Microsoft Intermediate Language (MSIL) code before delivering credential-stealing malware. On macOS, the malware uses multiple layers of Base64 encoding, compressed payloads, string obfuscation, and anti-analysis techniques, including anti-sandbox and anti-virtual machine checks. The final Mach-O payload functions as a backdoor capable of spawning /bin/bash or /bin/zsh shells, enabling remote command execution, system reconnaissance, payload deployment, and potential data exfiltration.

Attribution and Evolution:

Current analysis indicates that the campaign was facilitated through a compromised legitimate Google Ads advertiser account associated with a Malaysian organization, allowing the attackers to publish malicious advertisements that appeared trustworthy to users. There is currently no public attribution linking the operation to a specific threat actor or advanced persistent threat (APT) group. The campaign reflects an evolving trend in cybercrime, where threat actors increasingly exploit the popularity of artificial intelligence platforms and developer tools to increase the success of phishing and malware distribution campaigns. The use of trusted advertising platforms, counterfeit documentation, and platform-specific payloads demonstrates a high level of operational planning and adaptability.

Active Campaign and Geographic Spread:

At the time of publication, the campaign was observed targeting users globally through Google Search advertisements, with no evidence of country-specific targeting. Because the malicious advertisements appear in response to common search queries for Claude Code, any individual or organization searching for the software may be exposed. The attack specifically targets both Windows and macOS environments, indicating a broad victim profile that includes developers, IT professionals, researchers, and general users. Following responsible disclosure, the identified malicious advertiser account was reportedly disabled by Google. However, similar campaigns leveraging compromised advertising accounts and impersonated software documentation remain an ongoing threat.

Conclusion:

This campaign demonstrates that modern malware attacks increasingly rely on social engineering rather than software vulnerabilities, exploiting user trust in sponsored search results, well-known brands, and seemingly legitimate documentation. The abuse of trusted platforms such as Google Ads, coupled with operating system-specific malware and the use of legitimate system utilities, significantly increases the effectiveness of the attack while reducing the likelihood of detection. Organizations should strengthen user awareness, enforce secure software acquisition practices, restrict the execution of unauthorized scripts and command-line interpreters where feasible, and deploy Endpoint Detection and Response (EDR) solutions capable of identifying suspicious behaviors associated with this attack chain.

Impact:

Successful exploitation can result in the compromise of sensitive organizational and personal information. On Windows systems, the malware is capable of stealing credentials and other valuable data through multi-stage information-stealing payloads. On macOS, the installed backdoor provides attackers with persistent remote access, allowing them to execute arbitrary commands, deploy additional malware, conduct lateral movement, harvest credentials, and exfiltrate sensitive information. The compromise of privileged accounts or developer workstations may further increase the risk of unauthorized access to enterprise environments, cloud services, and software development resources.

IOC and Context Details:

Topics Details
Tactic Name Initial Access, Execution, Defense Evasion, Credential Access, Command and Control
Technique Name Phishing, User Execution, Command and Scripting Interpreter, Signed Binary Proxy Execution, Ingress Tool Transfer
Sub Technique Name ClickFix, PowerShell, Windows Command Shell (CMD), Unix Shell (zsh/bash), mshta.exe Abuse
Attack Type Malware
Targeted Applications Google Search, Google Ads, Claude Code, Web Browsers, PowerShell, Command Prompt (CMD), macOS Terminal (zsh/bash)
Region Impacted Global
Industry Impacted Technology, Software Development, IT Services, Developers, Enterprise
IOC's SHA-256 Hashes:
79cd21185c51a5bfe2cfebdc51e14b258d91549fc0e4e09b6939c2a8a1c5ac19
3b4d3a59024f14cf1f07395afd6957be05d125e00ae8fdcea3a5dee1d8ab9dd3
eb4d9a0e4c483dc29ae8c4d31fafcd583c457923d3344745b5c7ab13abed4dc5
505b32ac2b6fffb5fac81d5bdc2e1e8581fc4196dfb01aee852216a3ad6ff47e
762fb099115d1917b6f673cc5c74a4b61962a64d640673aaf02566ca6a3dbfa4
a78e487995ab452c5990b4baff6a4fa485ae2798c2ddd13718c17eb641f11646

URLs:
hxxps://claude-code-cmd.squarespace[.]com
hxxp://code.claude[.]ai/download/
hxxps://download.active-version[.]com/claude

Domains:
bernasibutuwqu2.com
briskinternet.com
isgilan.com
a2abotnet.com
customroofingcontractors.com
claude-code.official-version.com
jerryshvac.com
oaklandwaterdamage.com
thnikagent.com
babulikinet.com
loserrq0j1sha8.com
peowqlauoshau8.com
plirepsijr74.com
homeinspectionnaperville[.]com
yoauction[.]com
alabamarecoverycenter[.]com
5x5web[.]com
touristprogram[.]com
bewqslkslikrtjinfg9[.]com
CVE NA

Recommended Actions:

  • Download software only from official vendor websites or verified repositories, and avoid using sponsored search results as the primary source for software downloads.
  • Educate users, particularly developers and IT personnel, about ClickFix and other social engineering techniques that prompt the execution of PowerShell, Command Prompt, or terminal commands.
  • Verify website URLs and digital signatures before downloading software or executing installation commands to ensure they originate from legitimate sources.
  • Restrict or monitor the use of scripting engines and system utilities such as mshta.exe, PowerShell, Command Prompt (CMD), and shell interpreters where operationally feasible.
  • Deploy Endpoint Detection and Response (EDR) or Endpoint Protection Platform (EPP) solutions capable of detecting malicious scripts, suspicious process execution, and multi-stage malware activity.
  • Implement application control or allowlisting policies to prevent unauthorized scripts, executables, and binaries from running on enterprise endpoints.
  • Continuously monitor network traffic and endpoint telemetry for connections to suspicious or newly observed domains, and proactively block known Indicators of Compromise (IOCs) associated with this campaign.
  • Maintain up-to-date antivirus software, operating systems, and security controls, and ensure timely threat intelligence updates are applied to detect and block emerging malware variants.

Reference:

https://www.bitdefender.com/en-us/blog/labs/fake-claude-code-google-ads-malware

https://www.trendmicro.com/en_us/research/26/f/claudeai-shared-chat-abused-in-malvertising.html