CyberTech Intelligence

Bybit Reveals macOS Malware Targeting Claude Code Searches

Bybit Reveals macOS Malware Targeting Claude Code Searches

A new threat campaign is highlighting how attackers are exploiting developer behavior, as the Claude Code malware campaign targets macOS users searching for AI development tools.

Bybit disclosed findings from its Security Operations Center detailing a multi stage attack that uses search engine manipulation to lure victims. The campaign specifically targets users searching for “Claude Code,” an AI development tool from Anthropic, redirecting them to spoofed installation pages designed to mimic legitimate documentation.

First identified in March 2026, the attack begins with search engine optimization poisoning, allowing malicious domains to rank prominently in search results. Once users click through, they are presented with a convincing fake download page that initiates a two stage malware infection chain focused on credential theft and persistent system access.

The initial payload is delivered through a Mach O dropper that deploys an infostealer using osascript. Researchers observed behavior similar to known macOS threats such as AMOS and Banshee, with the malware extracting sensitive data including browser credentials, macOS Keychain entries, messaging sessions, VPN configurations, and cryptocurrency wallet information. The campaign specifically attempts to access more than 250 browser based wallet extensions along with multiple desktop wallet applications.

A second stage payload introduces a more advanced backdoor written in C plus plus. This component includes sandbox evasion techniques and encrypted runtime configurations, enabling it to remain hidden while maintaining long term access. It establishes persistence through system level agents and communicates with attacker infrastructure using HTTP based polling, allowing remote command execution on compromised devices.

According to David Zong, Head of Group Risk Control and Security at Bybit, “As one of the first crypto exchanges to publicly document this type of malware campaign, we believe sharing these findings is critical to strengthening collective defense across the industry. Our AI-assisted SOC allows us to move from detection to full kill chain visibility within a single operational window. What used to require a team of analysts working across multiple shifts – decompilation, IOC extraction, report drafting, rule writing – was completed in a single session with AI handling the heavy lifting and our analysts providing judgment and validation. Looking to the future, we will face an AI war. Using AI to defend against AI is an inevitable trend. Bybit will further increase its investment in AI for security, achieving minute-level threat detection and automated, intelligent emergency response.”

The investigation also uncovered social engineering tactics, including fake macOS password prompts used to capture credentials and attempts to replace legitimate wallet software with trojanized versions. The malware targets a broad set of environments, including Chromium based browsers, Firefox, Safari data, and local files containing financial or authentication information.

Bybit’s use of AI assisted workflows significantly accelerated the analysis process, reducing reverse engineering time and enabling same day deployment of detection measures. The company confirmed that malicious infrastructure was identified and mitigated within a single day, with public disclosure following shortly after.

The Claude Code malware campaign underscores a growing trend where attackers exploit search behavior and trusted tools to target developers. As AI adoption increases, such techniques are expected to become more prevalent, reinforcing the need for vigilance when downloading software and interacting with search results.



🔒 Login or Register to continue reading

cybertech-intelligence-logo-white

From Insights to Intelligence – A New Era Begins.

The cybersecurity landscape demands more than updates – it demands intelligence.

That’s why Cyber Technology Insights is evolving into Cyber Tech Intelligence, a next-generation platform for cybersecurity professionals who need to act, not just read.

Launching soon: www.cybertechintelligence.com

Our Services

GTM Strategy

Demand Intelligence

Pipeline Activation

Round Tables

Sponsored Research

Targeted Content

Webinars & Panels

Vendor Intelligence

Strategic Consulting

See Your Target Accounts Already in Market

We identify companies actively researching cybersecurity, CX, and enterprise tech solutions.

Includes sample accounts, intent signals, and activation strategy.

Access Real Buyer Intent Data for Cybersecurity & B2B Tech

Get a sample of verified in-market accounts, campaign benchmarks, and audience insights.

No spam. Only relevant insights and campaign data.

From Audience Engagement to Buying Group Intelligence to Pipeline Activation

CyberTech Intelligence helps you engage the right cybersecurity audience, decode buying group intent, and activate pipeline – all in one connected motion.

Where would you like to start?

Get Your Custom Audience & Pipeline Plan

We’ll share a sample audience, campaign benchmarks, and how we generate pipeline for companies like yours.