Cybercriminals have turned to search engine advertising as a delivery mechanism for malware, using fake ads for the Claude AI chatbot to compromise users on Google and Bing. The campaign, identified as Claude ClickFix, redirects victims through a chain of deceptive pages before prompting them to install what appears to be a legitimate update but is in fact malicious software.

What You Need to Know

This attack exploits trust in branded search results and the popularity of generative AI tools. Victims typically encounter these fake ads when searching for Claude on Google or Bing. The ClickFix technique presents a convincing browser error message that urges the user to download a “fix” that is actually a remote access trojan. Anyone using paid search results to find AI services should verify the URL before clicking.

How the ClickFix Campaign Operates

Hackers purchase ad placements on Google Ads and Bing that appear legitimate. When a user clicks the ad, they are sent through several redirects designed to obscure the final destination. The landing page impersonates the official Claude login portal. A pop-up then displays a fake browser error claiming the page is corrupted and advises the user to run a command to “fix” the issue.

This command copies and executes a malicious script from the clipboard, giving the attacker remote access to the victim’s machine. The technique is known as ClickFix and has been observed in multiple recent malvertising campaigns.

  • Malvertising chain: Attackers abuse Google Ads and Bing ad platforms to serve links that appear at the top of search results.
  • Fake error prompt: The landing page triggers a simulated browser error that tells users to press Windows Key + R and paste a command.
  • Clipboard hijack: The command pastes a PowerShell payload into the clipboard, which the user unknowingly executes.

Broader Trend of AI Themed Phishing

The popularity of AI chatbots like Claude has made them a prime target for impersonation. Cybercriminals frequently create fake login pages for ChatGPT, Gemini and now Claude. The use of pay per click ads adds an extra layer of credibility because users have been trained to trust sponsored results. Security researchers have noted a sharp rise in malvertising linked to generative AI tools as attackers race to capitalize on public demand.

Enterprises face a higher risk because employees searching for work related AI tools may inadvertently bypass corporate security controls. A single compromised machine can lead to data breaches or lateral movement inside a network.

Why This Matters

The Claude ClickFix campaign demonstrates how attackers are weaponizing trusted advertising channels to deliver remote access malware. For individuals, the direct consequence is potential credential theft, data loss and financial fraud. For organizations, the stakes include intellectual property theft and compliance violations. Search engines bear a responsibility to tighten ad vetting processes, but users must also adopt caution: treat every sponsored AI link as suspicious until verified. The shift from email phishing to search engine malvertising means that the threat vector is now embedded in everyday browsing behavior.

Protecting Against ClickFix Style Attacks

A few preventive steps can reduce the risk. Never run commands provided by a website or pop up. Bookmark the official Claude URL instead of relying on search results. Enable ad blockers for search engines to minimize exposure to malicious ads. Security teams should monitor for unusual PowerShell executions and block clipboard based command execution in enterprise environments.