Close Menu
    What's Hot

    MemeMax Officially Launches, Introducing a Meme-Native Perpetual Trading Infrastructure

    April 21, 2026

    Bybit Uncovers AI-Assisted macOS Malware Campaign Targeting Users Searching for Claude Code

    April 21, 2026

    Eightco Holdings (NASDAQ: ORBS) Reports Total Holdings of $336 Million, Includes $90 Million OpenAI, $25 Million MrBeast, More Than 11,000 ETH Coins and Over 283 Million WLD Tokens

    April 21, 2026
    Facebook X (Twitter) Instagram
    Trending
    • MemeMax Officially Launches, Introducing a Meme-Native Perpetual Trading Infrastructure
    • Bybit Uncovers AI-Assisted macOS Malware Campaign Targeting Users Searching for Claude Code
    • Eightco Holdings (NASDAQ: ORBS) Reports Total Holdings of $336 Million, Includes $90 Million OpenAI, $25 Million MrBeast, More Than 11,000 ETH Coins and Over 283 Million WLD Tokens
    • HashKey Group Releases 3rd Web3 Economy Whitepaper: Reconstructing On-Chain Finance and Tokenization Infrastructure for the AI Agent Economy Era
    • Bybit Introduces Premier Loans, Democratizing Enterprise-Grade Capital Solutions
    • Mantle Confirms Full Network Security and Coordinates Recovery With Aave, Including Potential Treasury Participation Following rsETH by KelpDAO Incident
    • MetaComp launches the world’s first AI agent governance framework for regulated financial services
    • Tokenized Cash Management Advisory Group Publishes Core Principles for Digital Money
    • Home
    • Contact Us
    Block KSABlock KSA
    • AI

      Apple’s revolutionary AI integration propels stock to new heights

      June 12, 2024

      OpenAI and News Corp. ink historic deal to enhance AI journalism

      May 23, 2024

      Data centers drive AI, crypto, pose climate risk

      April 20, 2024

      Meta platforms ramps up AI arsenal in bid for industry lead

      April 19, 2024

      Microsoft’s $1.5 billion boost – G42 and AI partnership goes global

      April 16, 2024
    • Bitcoin & Altcoins

      Bitcoin tops $70,000 as Wall Street expands crypto

      April 7, 2026

      Bitcoin rebound lifts crypto stocks on ETF inflows

      March 17, 2026

      Trump backs crypto firms as banks fight stablecoin yield

      March 7, 2026

      Bitcoin drops below $65,000 after U.S. tariff reset

      February 23, 2026

      South Korean crypto exchange mistakenly sends $40bn in bitcoin

      February 9, 2026
    • Blockchain & DeFi

      Bybit confirms $1.4 billion hack targeting Ethereum cold wallet

      February 21, 2025

      Google Cloud’s web3 portal launch sparks debate in crypto industry

      April 28, 2024

      Crypto trader Avi Eisenberg found guilty of $110m fraud

      April 18, 2024

      Fear and hope as Binance leaves Nigerian market

      March 11, 2024

      DeFi TVL surpasses $100 billion milestone amid crypto rally

      March 10, 2024
    • Business

      Gen Z lifts crypto adoption as digital assets expand

      April 8, 2026

      DDSC dirham-backed stablecoin approved for ADI Chain

      February 12, 2026

      Institutional investors focus on Bitcoin inflows

      October 25, 2025

      EU judicial group targets crypto use in money laundering operations

      October 16, 2025

      Morgan Stanley taps Zerohash to power crypto trading on ETrade

      September 24, 2025
    • Ethereum & NFTs

      Hong Kong ETF market makes waves with debut of crypto funds

      April 30, 2024

      Manchester City and Okx launch digital collectibles for global fans

      April 23, 2024

      Ethereum surges past $3,600 mark amidst strong trading activity

      April 8, 2024

      Ether’s value could see significant upswing after Bitcoin halving

      April 6, 2024

      Binance NFT announces halt on bitcoin NFT support

      April 4, 2024
    • FinTech

      Binance expands trading pairs with four new launches in September

      September 3, 2024

      Ripple releases another 1 billion XRP as market questions grow

      September 3, 2024

      Rakeez Financial secures $2M seed round led by CoreVision

      March 15, 2024

      Trampay gets $250K from Potencia Ventures, boosts Brazil gig economy

      March 11, 2024

      Nigeria welcomes PalmPay’s game-changing fintech offerings

      March 11, 2024
    • Gaming

      Immutable unveils $50 million Web3 gaming rewards program

      April 26, 2024

      ViewSonic unveils XG272-2K-OLED, redefining gaming visuals

      April 2, 2024

      Animoca Brands, KACST forge alliance for web3 hub in Riyadh

      March 11, 2024

      Hitachi LG data storage redefines console gaming storage

      February 28, 2024

      Sony’s stock plummets by $10 billion as PS5 sales forecast dips

      February 19, 2024
    • Partner Content

      Bitget Signals Next Phase of Exchanges With TradFi Integration

      March 13, 2026

      Bitget Expands Into TradFi, Bringing Multi-Asset Trading to MENA Users

      February 23, 2026

      Dollar Cost Averaging (DCA): The Smart Crypto Investment Strategy Using Bybit’s Trading Bots

      December 18, 2025

      Stablecoins Emerge as a Key Financial Hedge Against Inflation Across Africa

      December 18, 2025

      Introducing TokenRun, Powered by GEODNET RTK

      December 8, 2025
    • Policy

      China extends crypto ban to stablecoins and tokenized assets

      February 9, 2026

      SEC streamlines crypto ETF listing rules for US exchanges

      September 22, 2025

      Trump administration orders crypto assets to count for mortgages

      June 28, 2025

      US Senate passes GENIUS Act in crypto industry breakthrough

      June 21, 2025

      Crypto Strategic Reserve set to reshape U.S. financial policy

      March 3, 2025
    Block KSABlock KSA
    Home » Bybit Uncovers AI-Assisted macOS Malware Campaign Targeting Users Searching for Claude Code
    PR Newswire

    Bybit Uncovers AI-Assisted macOS Malware Campaign Targeting Users Searching for Claude Code

    April 21, 20264 Mins Read
    Share Facebook Twitter WhatsApp Pinterest Copy Link LinkedIn Tumblr Email Telegram

    DUBAI, UAE, April 21, 2026 /PRNewswire/ — Bybit, the world’s second-largest cryptocurrency exchange by trading volume, reported that its Security Operations Center (SOC) disclosed findings detailing a sophisticated, multi-stage malware campaign targeting macOS users searching for “Claude Code,” an AI-powered development tool from Anthropic.

    The report marks one of the first known disclosures by a centralized crypto exchange (CEX) of an active threat campaign targeting developers via AI tool discovery channels, underscoring the sector’s growing role in frontline cybersecurity intelligence.

    First identified in March 2026, the campaign used search engine optimization (SEO) poisoning to elevate a malicious domain to the top of Google search results. Users were redirected to a spoofed installation page designed to closely resemble legitimate documentation, triggering a two-stage attack chain focused on credential harvesting, crypto asset targeting, and persistent system access.

    Bybit Uncovers AI-Assisted macOS Malware Campaign Targeting Users Searching for Claude Code

     

    Bybit Uncovers AI-Assisted macOS Malware Campaign Targeting Users Searching for Claude Code

    The initial payload, delivered via a Mach-O dropper, deployed an osascript-based infostealer exhibiting characteristics similar to known AMOS and Banshee variants. It executed a multi-phase obfuscation sequence to extract sensitive data including browser credentials, macOS Keychain entries, Telegram sessions, VPN profiles, and cryptocurrency wallet information. Bybit researchers identified targeted access attempts against more than 250 browser-based wallet extensions and multiple desktop wallet applications.

    A second-stage payload introduced a C++-based backdoor with advanced evasion capabilities, including sandbox detection and encrypted runtime configurations. The malware established persistence through system-level agents and enabled remote command execution via HTTP-based polling, granting attackers ongoing control over compromised devices.

    Bybit’s SOC leveraged AI-assisted workflows across the full malware analysis lifecycle, significantly accelerating response time while maintaining analytical depth. Initial triage and classification of the Mach-O sample were completed within minutes, with models flagging behavioral similarities to known malware families.

    AI-assisted reverse engineering and control-flow analysis reduced the time required for deep inspection of the second-stage backdoor from an estimated six to eight hours to under 40 minutes. At the same time, automated extraction pipelines identified indicators of compromise (IOCs) – including command-and-control infrastructure, file signatures, and behavioral patterns – and mapped them to established threat frameworks.

    These capabilities enabled same-day deployment of detection measures. AI-assisted rule generation supported the creation of threat signatures and endpoint detection rules, which analysts validated before being pushed into production environments. AI-generated reporting drafts further reduced turnaround time, allowing threat intelligence outputs to be finalized approximately 70% faster than traditional workflows.

    “As one of the first crypto exchanges to publicly document this type of malware campaign, we believe sharing these findings is critical to strengthening collective defense across the industry,” said David Zong, Head of Group Risk Control and Security at Bybit. “Our AI-assisted SOC allows us to move from detection to full kill chain visibility within a single operational window. What used to require a team of analysts working across multiple shifts – decompilation, IOC extraction, report drafting, rule writing – was completed in a single session with AI handling the heavy lifting and our analysts providing judgment and validation.”

    The investigation also revealed social engineering tactics, including fake macOS password prompts used to validate and cache user credentials. In some cases, attackers attempted to replace legitimate crypto wallet applications such as Ledger Live and Trezor Suite with trojanized versions hosted on malicious infrastructure.

    The malware targeted a wide range of environments, including Chromium-based browsers, Firefox variants, Safari data, Apple Notes, and local file directories commonly used to store sensitive financial or authentication data.

    Bybit identified multiple domains and command-and-control endpoints associated with the campaign, all of which have been defanged for public disclosure. Analysis indicates that attackers relied on intermittent HTTP polling rather than persistent connections, making detection more challenging.

    The incident reflects a growing trend of attackers targeting developers through manipulated search results, particularly as AI tools gain mainstream adoption. Developers remain high-value targets due to their access to codebases, infrastructure, and financial systems.

    Bybit confirmed that malicious infrastructure was identified on March 12, with full analysis, mitigation, and detection measures completed within the same day. Public disclosure followed on March 20, alongside detailed detection guidance.

    #Bybit / #CryptoArk / #NewFinancialPlatform

    About Bybit

    Bybit is the world’s second-largest cryptocurrency exchange by trading volume, serving a global community of over 80 million users. Founded in 2018, Bybit is redefining openness in the decentralized world by creating a simpler, open and equal ecosystem for everyone. With a strong focus on Web3, Bybit partners strategically with leading blockchain protocols to provide robust infrastructure and drive on-chain innovation. Renowned for its secure custody, diverse marketplaces, intuitive user experience, and advanced blockchain tools, Bybit bridges the gap between TradFi and DeFi, empowering builders, creators, and enthusiasts to unlock the full potential of Web3. Discover the future of decentralized finance at Bybit.com.

    For more details about Bybit, please visit Bybit Press
    For media inquiries, please contact: media@bybit.com
    For updates, please follow: Bybit’s Communities and Social Media

    Discord | Facebook | Instagram | LinkedIn | Reddit | Telegram | TikTok | X | Youtube

    Photo – https://mma.prnewswire.com/media/2961757/Image.jpg
    Photo – https://mma.prnewswire.com/media/2961756/Bybit_Uncovers_AI_Assisted_macOS_Malware_Campaign_Targeting_Users_Searching_Claude.jpg
    Logo – https://mma.prnewswire.com/media/2932256/Bybit_TNFP_Logo.jpg

    Cision View original content:https://www.prnewswire.co.uk/news-releases/bybit-uncovers-ai-assisted-macos-malware-campaign-targeting-users-searching-for-claude-code-302748784.html

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

    Related Posts

    MemeMax Officially Launches, Introducing a Meme-Native Perpetual Trading Infrastructure

    April 21, 2026

    Eightco Holdings (NASDAQ: ORBS) Reports Total Holdings of $336 Million, Includes $90 Million OpenAI, $25 Million MrBeast, More Than 11,000 ETH Coins and Over 283 Million WLD Tokens

    April 21, 2026

    HashKey Group Releases 3rd Web3 Economy Whitepaper: Reconstructing On-Chain Finance and Tokenization Infrastructure for the AI Agent Economy Era

    April 21, 2026
    Latest News

    Gen Z lifts crypto adoption as digital assets expand

    April 8, 2026

    Bitcoin tops $70,000 as Wall Street expands crypto

    April 7, 2026

    Bitcoin rebound lifts crypto stocks on ETF inflows

    March 17, 2026

    Trump backs crypto firms as banks fight stablecoin yield

    March 7, 2026

    Bitcoin drops below $65,000 after U.S. tariff reset

    February 23, 2026

    DDSC dirham-backed stablecoin approved for ADI Chain

    February 12, 2026

    South Korean crypto exchange mistakenly sends $40bn in bitcoin

    February 9, 2026

    China extends crypto ban to stablecoins and tokenized assets

    February 9, 2026
    Policy

    China extends crypto ban to stablecoins and tokenized assets

    February 9, 2026

    SEC streamlines crypto ETF listing rules for US exchanges

    September 22, 2025

    Trump administration orders crypto assets to count for mortgages

    June 28, 2025

    US Senate passes GENIUS Act in crypto industry breakthrough

    June 21, 2025
    Blockchain & DeFi

    Bybit confirms $1.4 billion hack targeting Ethereum cold wallet

    February 21, 2025

    Google Cloud’s web3 portal launch sparks debate in crypto industry

    April 28, 2024

    Crypto trader Avi Eisenberg found guilty of $110m fraud

    April 18, 2024

    Fear and hope as Binance leaves Nigerian market

    March 11, 2024
    Business

    Gen Z lifts crypto adoption as digital assets expand

    April 8, 2026

    DDSC dirham-backed stablecoin approved for ADI Chain

    February 12, 2026

    Institutional investors focus on Bitcoin inflows

    October 25, 2025

    EU judicial group targets crypto use in money laundering operations

    October 16, 2025
    © 2024 Block KSA | All Rights Reserved
    • Home
    • Contact Us

    Type above and press Enter to search. Press Esc to cancel.