Google Ads and Bing redirect abuse delivers fake Claude ClickFix installers
Push Security detected a customer-environment attack in which a Google advertisement displaying bing.com routed users through a Bing search-result redirect and compromised WordPress site to a fake Claude macOS installer. The new delivery detail is search-engine redirect abuse with referrer and browser-header cloaking, rather than poisoned shared AI conversations. The installer displayed a legitimate command but copied a malicious shell command to the clipboard. The report does not establish the final malware payload or successful endpoint compromise.