Bybit Uncovers macOS Malware Targeting Users Searching for Claude Code
The Bybit Security Operations Center disclosed a sophisticated malware campaign targeting macOS users searching for Claude Code, . The operation used search engine optimization poisoning to push a malicious domain to the top of search results, redirecting users to a fake installation page.
The malware executed a two-stage attack that harvested credentials, targeted cryptocurrency wallets, and maintained persistent access to infected systems. The first stage delivered a Mach-O dropper using an osascript-based infostealer similar to AMOS and Banshee variants. It extracted browser data, macOS Keychain entries, Telegram sessions, and wallet information from over 250 browser and desktop wallet applications.
A second-stage payload introduced a C++ backdoor capable of sandbox detection and encrypted configuration management. It used HTTP polling for remote command execution and persistence through system-level agents. Attackers also used fake macOS password prompts and trojanized versions of legitimate wallet applications such as Ledger Live and Trezor Suite.
Bybit reported that its AI-assisted workflows accelerated malware analysis, reducing deep inspection time from several hours to under 40 minutes. Automated extraction pipelines identified indicators of compromise and enabled same-day deployment of detection rules. The malicious infrastructure was identified on March 12, with full mitigation completed within the same day.
We hope you enjoyed this article
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.
Also, consider following us on social media:
More from Cybersecurity
Sep 16 AV-Comparatives Certifies 11 Endpoint Security Products in 2026 Test Sep 16 Cohesity Adds AI Agent Backup and Recovery to Data Cloud Sep 15 Hexnode Introduces Synapse for IT and Security Operations Sep 15 Cisco Expands Splunk AI for Private and Isolated Environments Sep 15 Zip Security Joins CrowdStrike Coalition to Protect Small BusinessesCybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Market report
2025 Generative AI in Professional Services Report
Thomson Reuters
This report by Thomson Reuters explores the integration and impact of generative AI technologies, such as ChatGPT and Microsoft Copilot, within the professional services sector. It highlights the growing adoption of GenAI tools across industries like legal, tax, accounting, and government, and discusses the challenges and opportunities these technologies present. The report also examines professionals' perceptions of GenAI and the need for strategic integration to maximize its value.
Read moreYou may also like
Anthropic Signs Out Claude Users After Infostealer Session Thefts
US Agencies Accuse Chinese AI Firms of Industrial Scale Model Distillation
Anthropic Publishes Five Cases of Claude Use That Could Support Biological Weapons Work
Anthropic Attributes Its Largest Measured Distillation Campaign to Alibaba
Anthropic's Threat Report Finds AI Moving From Assistant to Orchestrator
Daily AI Brief: the AI news that matters, in your inbox.