Bybit Uncovers macOS Malware Targeting Users Searching for Claude Code
The Bybit Security Operations Center disclosed a sophisticated malware campaign targeting macOS users searching for Claude Code, . The operation used search engine optimization poisoning to push a malicious domain to the top of search results, redirecting users to a fake installation page.
The malware executed a two-stage attack that harvested credentials, targeted cryptocurrency wallets, and maintained persistent access to infected systems. The first stage delivered a Mach-O dropper using an osascript-based infostealer similar to AMOS and Banshee variants. It extracted browser data, macOS Keychain entries, Telegram sessions, and wallet information from over 250 browser and desktop wallet applications.
A second-stage payload introduced a C++ backdoor capable of sandbox detection and encrypted configuration management. It used HTTP polling for remote command execution and persistence through system-level agents. Attackers also used fake macOS password prompts and trojanized versions of legitimate wallet applications such as Ledger Live and Trezor Suite.
Bybit reported that its AI-assisted workflows accelerated malware analysis, reducing deep inspection time from several hours to under 40 minutes. Automated extraction pipelines identified indicators of compromise and enabled same-day deployment of detection rules. The malicious infrastructure was identified on March 12, with full mitigation completed within the same day.
We hope you enjoyed this article.
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.
Also, consider following us on social media:
More from: Cybersecurity
Subscribe to Cybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Trend report
Cybersecurity Trends Report 2025
The Cybersecurity Trends Report 2025 by Netwrix Research Lab provides insights into how organizations are adapting their cybersecurity strategies amidst growing AI adoption. The report, based on a survey of 2,150 IT professionals from 121 countries, highlights key trends such as the increase in hybrid IT environments, AI-driven security challenges, and the rising costs of security incidents.
Read more