Connect with us

Technology

AI empowered Bybit Security Team Uncovers macOS Malware Campaign Targeting Users Searching for Claude Code

Published

on

/C O R R E C T I O N — Bybit/

In the news release, Bybit Uncovers AI-Assisted macOS Malware Campaign Targeting Users Searching for Claude Code, issued 21-Apr-2026 by Bybit over PR Newswire, we are advised by the company that the headline and 9th paragraph have been updated. The complete, corrected release follows:

DUBAI, UAE, April 21, 2026 /CNW/ — Bybit, the world’s second-largest cryptocurrency exchange by trading volume, reported that its Security Operations Center (SOC) disclosed findings detailing a sophisticated, multi-stage malware campaign targeting macOS users searching for “Claude Code,” an AI-powered development tool from Anthropic.

The report marks one of the first known disclosures by a centralized crypto exchange (CEX) of an active threat campaign targeting developers via AI tool discovery channels, underscoring the sector’s growing role in frontline cybersecurity intelligence.

First identified in March 2026, the campaign used search engine optimization (SEO) poisoning to elevate a malicious domain to the top of Google search results. Users were redirected to a spoofed installation page designed to closely resemble legitimate documentation, triggering a two-stage attack chain focused on credential harvesting, crypto asset targeting, and persistent system access.

 

The initial payload, delivered via a Mach-O dropper, deployed an osascript-based infostealer exhibiting characteristics similar to known AMOS and Banshee variants. It executed a multi-phase obfuscation sequence to extract sensitive data including browser credentials, macOS Keychain entries, Telegram sessions, VPN profiles, and cryptocurrency wallet information. Bybit researchers identified targeted access attempts against more than 250 browser-based wallet extensions and multiple desktop wallet applications.

A second-stage payload introduced a C++-based backdoor with advanced evasion capabilities, including sandbox detection and encrypted runtime configurations. The malware established persistence through system-level agents and enabled remote command execution via HTTP-based polling, granting attackers ongoing control over compromised devices.

Bybit’s SOC leveraged AI-assisted workflows across the full malware analysis lifecycle, significantly accelerating response time while maintaining analytical depth. Initial triage and classification of the Mach-O sample were completed within minutes, with models flagging behavioral similarities to known malware families.

AI-assisted reverse engineering and control-flow analysis reduced the time required for  deep inspection of the second-stage backdoor from an estimated six to eight hours to under 40 minutes. At the same time, automated extraction pipelines identified indicators of compromise (IOCs) – including command-and-control infrastructure, file signatures, and behavioral patterns – and mapped them to established threat frameworks.

These capabilities enabled same-day deployment of detection measures. AI-assisted rule generation supported the creation of threat signatures and endpoint detection rules, which analysts validated before being pushed into production environments. AI-generated reporting drafts further reduced turnaround time, allowing threat intelligence outputs to be finalized approximately 70% faster than traditional workflows.

“As one of the first crypto exchanges to publicly document this type of malware campaign, we believe sharing these findings is critical to strengthening collective defense across the industry,” said David Zong, Head of Group Risk Control and Security at Bybit. “Our AI-assisted SOC allows us to move from detection to full kill chain visibility within a single operational window. What used to require a team of analysts working across multiple shifts – decompilation, IOC extraction, report drafting, rule writing – was completed in a single session with AI handling the heavy lifting and our analysts providing judgment and validation.  Looking to the future, we will face an AI war. Using AI to defend against AI is an inevitable trend. Bybit will further increase its investment in AI for security, achieving minute-level threat detection and automated, intelligent emergency response.”

The investigation also revealed social engineering tactics, including fake macOS password prompts used to validate and cache user credentials. In some cases, attackers attempted to replace legitimate crypto wallet applications such as Ledger Live and Trezor Suite with trojanized versions hosted on malicious infrastructure.

The malware targeted a wide range of environments, including Chromium-based browsers, Firefox variants, Safari data, Apple Notes, and local file directories commonly used to store sensitive financial or authentication data.

Bybit identified multiple domains and command-and-control endpoints associated with the campaign, all of which have been defanged for public disclosure. Analysis indicates that attackers relied on intermittent HTTP polling rather than persistent connections, making detection more challenging.

The incident reflects a growing trend of attackers targeting developers through manipulated search results, particularly as AI tools gain mainstream adoption. Developers remain high-value targets due to their access to codebases, infrastructure, and financial systems.

Bybit confirmed that malicious infrastructure was identified on March 12, with full analysis, mitigation, and detection measures completed within the same day. Public disclosure followed on March 20, alongside detailed detection guidance.

#Bybit / #CryptoArk / #NewFinancialPlatform

About Bybit

Bybit is the world’s second-largest cryptocurrency exchange by trading volume, serving a global community of over 80 million users. Founded in 2018, Bybit is redefining openness in the decentralized world by creating a simpler, open and equal ecosystem for everyone. With a strong focus on Web3, Bybit partners strategically with leading blockchain protocols to provide robust infrastructure and drive on-chain innovation. Renowned for its secure custody, diverse marketplaces, intuitive user experience, and advanced blockchain tools, Bybit bridges the gap between TradFi and DeFi, empowering builders, creators, and enthusiasts to unlock the full potential of Web3. Discover the future of decentralized finance at Bybit.com.

For more details about Bybit, please visit Bybit Press
For media inquiries, please contact: media@bybit.com
For updates, please follow: Bybit’s Communities and Social Media

Discord | Facebook | Instagram | LinkedIn | Reddit | Telegram | TikTok | X | Youtube

View original content to download multimedia:https://www.prnewswire.com/news-releases/ai-empowered-bybit-security-team-uncovers-macos-malware-campaign-targeting-users-searching-for-claude-code-302748925.html

SOURCE Bybit

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

IGCS International Announces Strategic Equity Investment by Lacks Enterprises

Published

on

By

DALLAS, April 22, 2026 /PRNewswire/ — IGCS International, a CVE-certified SDVOSB and leading provider of mission support and MRO supplies to the U.S. Department of Defense and federal agencies, today announced that Lacks Enterprises has acquired an equity stake in the company.

The strategic investment combines IGCS’s expertise in government supply chain, logistics, and MRO solutions with Lacks Enterprises’ advanced manufacturing capabilities, including electroplating, injection molding, composites, and testing for aerospace and defense.

“IGCS has built a strong track record supporting the Department of Defense… Partnering with Lacks Enterprises allows us to integrate cutting-edge manufacturing innovation into our offerings,” said Russ Spears, President of IGCS International.

Media Contact: Russ Spears, 214-733-7278, russ@igcsintl.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/igcs-international-announces-strategic-equity-investment-by-lacks-enterprises-302750824.html

SOURCE IGCS International

Continue Reading

Technology

Shoulder Innovations to Report First Quarter 2026 Financial Results on May 13, 2026

Published

on

By

GRAND RAPIDS, Mich., April 22, 2026 /PRNewswire/ — Shoulder Innovations, Inc. (“Shoulder Innovations”) (NYSE: SI), a commercial-stage medical technology company exclusively focused on transforming the shoulder surgical care market, today announced it will release financial results for the first quarter of 2026 after market close on Wednesday, May 13, 2026.

Management will host a conference call to discuss financial results beginning at 4:30 p.m. ET / 1:30 p.m. PT on May 13, 2026. Those interested in listening to the conference call may do so by dialing (877) 407-8216 for domestic callers or (412) 902-1015 for international callers and providing access code 13759613. A live and archived webcast of the event will be available in the “Investor Relations” section of the Shoulder Innovations website at https://ir.shoulderinnovations.com/.

About Shoulder Innovations
Shoulder Innovations is a commercial-stage medical technology company exclusively focused on transforming the shoulder surgical care market, with a current offering of advanced implant systems for shoulder arthroplasty. These systems are a core element of Shoulder Innovations’ ecosystem, which is designed to improve core components of shoulder surgical care – preoperative planning, implant design and procedural efficiency – to benefit each stakeholder in the care chain. Shoulder Innovations’ ecosystem is also comprised of enabling technologies, efficient instrument systems, specialized support and surgeon-to-surgeon collaboration. Together, these elements seek to address the long-standing clinical and operational challenges in the shoulder surgical care market by delivering predictable outcomes, procedural simplicity, and efficiency across all sites of care.

Contact
Brian Johnston or Sam Bentzinger 
Gilmartin Group LLC 
ir@shoulderinnovations.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/shoulder-innovations-to-report-first-quarter-2026-financial-results-on-may-13-2026-302750154.html

SOURCE Shoulder Innovations

Continue Reading

Technology

Accuray to Report Third Quarter Fiscal 2026 Financial Results on May 6, 2026

Published

on

By

MADISON, Wis., April 22, 2026 /PRNewswire/ — Accuray Incorporated (NASDAQ: ARAY) will report financial results for the third quarter of fiscal year 2026, ended March 31, 2026, during a conference call hosted by company management at 1:30 p.m. PT/4:30 p.m. ET on May 6, 2026.

The conference call dial-in numbers are 1-833-316-0563 (USA) or 1-412-317-5747 (international). In addition, a dial-up replay of the conference call will be available approximately one hour after the call’s conclusion for one week. The replay number is 1-855-669-9658 (USA) or 1-412-317-0088 (international), conference ID: 4178502.

A live webcast of the call will also be available from the Investor Relations section of the company’s website at investors.accuray.com. A webcast replay can be accessed on the website and will remain available until Accuray announces its results for the fourth quarter of fiscal 2026.

About Accuray
Accuray is committed to expanding the powerful potential of radiation therapy to improve as many lives as possible. We invent unique, market-changing solutions designed to deliver radiation treatments for even the most complex cases—while making commonly treatable cases even easier—to meet the full spectrum of patient needs. We are dedicated to continuous innovation in radiation therapy for oncology, neuro-radiosurgery, and beyond, as we partner with clinicians and administrators, empowering them to help patients get back to their lives, faster. Accuray is headquartered in Madison, Wisconsin, with facilities worldwide. To learn more, visit www.accuray.com or follow us on Facebook, LinkedIn, X, and YouTube.

Investor and Media Contact
Steve Monroe
VP, Financial Planning & Analysis, Accuray
Investor.relations@accuray.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/accuray-to-report-third-quarter-fiscal-2026-financial-results-on-may-6-2026-302750641.html

SOURCE Accuray Incorporated

Continue Reading

Trending