Connect with us

Technology

AI empowered Bybit Security Team Uncovers macOS Malware Campaign Targeting Users Searching for Claude Code

Published

on

/C O R R E C T I O N — Bybit/

In the news release, Bybit Uncovers AI-Assisted macOS Malware Campaign Targeting Users Searching for Claude Code, issued 21-Apr-2026 by Bybit over PR Newswire, we are advised by the company that the headline and 9th paragraph have been updated. The complete, corrected release follows:

DUBAI, UAE, April 21, 2026 /CNW/ — Bybit, the world’s second-largest cryptocurrency exchange by trading volume, reported that its Security Operations Center (SOC) disclosed findings detailing a sophisticated, multi-stage malware campaign targeting macOS users searching for “Claude Code,” an AI-powered development tool from Anthropic.

The report marks one of the first known disclosures by a centralized crypto exchange (CEX) of an active threat campaign targeting developers via AI tool discovery channels, underscoring the sector’s growing role in frontline cybersecurity intelligence.

First identified in March 2026, the campaign used search engine optimization (SEO) poisoning to elevate a malicious domain to the top of Google search results. Users were redirected to a spoofed installation page designed to closely resemble legitimate documentation, triggering a two-stage attack chain focused on credential harvesting, crypto asset targeting, and persistent system access.

 

The initial payload, delivered via a Mach-O dropper, deployed an osascript-based infostealer exhibiting characteristics similar to known AMOS and Banshee variants. It executed a multi-phase obfuscation sequence to extract sensitive data including browser credentials, macOS Keychain entries, Telegram sessions, VPN profiles, and cryptocurrency wallet information. Bybit researchers identified targeted access attempts against more than 250 browser-based wallet extensions and multiple desktop wallet applications.

A second-stage payload introduced a C++-based backdoor with advanced evasion capabilities, including sandbox detection and encrypted runtime configurations. The malware established persistence through system-level agents and enabled remote command execution via HTTP-based polling, granting attackers ongoing control over compromised devices.

Bybit’s SOC leveraged AI-assisted workflows across the full malware analysis lifecycle, significantly accelerating response time while maintaining analytical depth. Initial triage and classification of the Mach-O sample were completed within minutes, with models flagging behavioral similarities to known malware families.

AI-assisted reverse engineering and control-flow analysis reduced the time required for  deep inspection of the second-stage backdoor from an estimated six to eight hours to under 40 minutes. At the same time, automated extraction pipelines identified indicators of compromise (IOCs) – including command-and-control infrastructure, file signatures, and behavioral patterns – and mapped them to established threat frameworks.

These capabilities enabled same-day deployment of detection measures. AI-assisted rule generation supported the creation of threat signatures and endpoint detection rules, which analysts validated before being pushed into production environments. AI-generated reporting drafts further reduced turnaround time, allowing threat intelligence outputs to be finalized approximately 70% faster than traditional workflows.

“As one of the first crypto exchanges to publicly document this type of malware campaign, we believe sharing these findings is critical to strengthening collective defense across the industry,” said David Zong, Head of Group Risk Control and Security at Bybit. “Our AI-assisted SOC allows us to move from detection to full kill chain visibility within a single operational window. What used to require a team of analysts working across multiple shifts – decompilation, IOC extraction, report drafting, rule writing – was completed in a single session with AI handling the heavy lifting and our analysts providing judgment and validation.  Looking to the future, we will face an AI war. Using AI to defend against AI is an inevitable trend. Bybit will further increase its investment in AI for security, achieving minute-level threat detection and automated, intelligent emergency response.”

The investigation also revealed social engineering tactics, including fake macOS password prompts used to validate and cache user credentials. In some cases, attackers attempted to replace legitimate crypto wallet applications such as Ledger Live and Trezor Suite with trojanized versions hosted on malicious infrastructure.

The malware targeted a wide range of environments, including Chromium-based browsers, Firefox variants, Safari data, Apple Notes, and local file directories commonly used to store sensitive financial or authentication data.

Bybit identified multiple domains and command-and-control endpoints associated with the campaign, all of which have been defanged for public disclosure. Analysis indicates that attackers relied on intermittent HTTP polling rather than persistent connections, making detection more challenging.

The incident reflects a growing trend of attackers targeting developers through manipulated search results, particularly as AI tools gain mainstream adoption. Developers remain high-value targets due to their access to codebases, infrastructure, and financial systems.

Bybit confirmed that malicious infrastructure was identified on March 12, with full analysis, mitigation, and detection measures completed within the same day. Public disclosure followed on March 20, alongside detailed detection guidance.

#Bybit / #CryptoArk / #NewFinancialPlatform

About Bybit

Bybit is the world’s second-largest cryptocurrency exchange by trading volume, serving a global community of over 80 million users. Founded in 2018, Bybit is redefining openness in the decentralized world by creating a simpler, open and equal ecosystem for everyone. With a strong focus on Web3, Bybit partners strategically with leading blockchain protocols to provide robust infrastructure and drive on-chain innovation. Renowned for its secure custody, diverse marketplaces, intuitive user experience, and advanced blockchain tools, Bybit bridges the gap between TradFi and DeFi, empowering builders, creators, and enthusiasts to unlock the full potential of Web3. Discover the future of decentralized finance at Bybit.com.

For more details about Bybit, please visit Bybit Press
For media inquiries, please contact: media@bybit.com
For updates, please follow: Bybit’s Communities and Social Media

Discord | Facebook | Instagram | LinkedIn | Reddit | Telegram | TikTok | X | Youtube

View original content to download multimedia:https://www.prnewswire.com/news-releases/ai-empowered-bybit-security-team-uncovers-macos-malware-campaign-targeting-users-searching-for-claude-code-302748925.html

SOURCE Bybit

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Baidu to Report First Quarter 2026 Financial Results on May 18, 2026

Published

on

By

BEIJING, April 23, 2026 /PRNewswire/ — Baidu, Inc. (Nasdaq: BIDU; HKEX: 9888 (HKD Counter) and 89888 (RMB Counter)) (“Baidu” or the “Company”), a leading AI company with strong Internet foundation, today announced that it will report its financial results for the First Quarter 2026 ended March 31, 2026, before the U.S. market opens on May 18, 2026. Baidu’s management will hold an earnings conference call at 8:00 AM on May 18, 2026, U.S. Eastern Time (8:00 PM on May 18, 2026, Beijing Time).

Please register in advance of the conference call using the link provided below. It will automatically direct you to the registration page of “Baidu Inc. Q1 2026 Earnings Conference Call”. Please follow the steps to enter your registration details, then click “Register”. Upon registering, you will then be provided with the dial-in number, the passcode, and your unique access PIN. This information will also be emailed to you as a calendar invite.

For pre-registration, please click:
https://s1.c-conf.com/diamondpass/10054331-iu876y.html

In the 10 minutes prior to the call start time, you may use the conference access information (including dial-in number(s), the passcode and unique access PIN) provided in the calendar invite that you have received following your pre-registration.

Additionally, a live and archived webcast of this conference call will be available at https://ir.baidu.com.

A replay of the conference call may be accessed by phone at the following number until May 25, 2026:
US: 1 855 883 1031
Reply PIN: 10054331

About Baidu

Founded in 2000, Baidu’s mission is to make the complicated world simpler through technology. Baidu is a leading AI company with strong Internet foundation, trading on Nasdaq under “BIDU” and the HKEX under “9888.” One Baidu ADS represents eight Class A ordinary shares.

View original content:https://www.prnewswire.com/news-releases/baidu-to-report-first-quarter-2026-financial-results-on-may-18-2026-302751204.html

SOURCE Baidu, Inc.

Continue Reading

Technology

Phase 1 of 139th Canton Fair Introduces New Dedicated Product Zones as Emerging Technologies Take Center Stage

Published

on

By

GUANGZHOU, China, April 23, 2026 /PRNewswire/ — The 139th China Import and Export Fair (Canton Fair) has further optimized its exhibition landscape with nine new dedicated product zones, reflecting ongoing structural shifts in global trade and the continued upgrading of China’s export portfolio.

Among the most closely watched additions in Phase 1 are the consumer and agricultural drone zones, both making their debut at the Canton Fair and offering a focused showcase of applications in the low‑altitude economy. The consumer drone zone showcases progress in flight control, AI‑based obstacle avoidance and energy efficiency across imaging, tourism, emergency response and patrol. The agricultural drone zone highlights precision farming, with spraying, seeding and field‑management demonstrations showing terrain‑following, intelligent route planning, and precise payload control.

On day one, a Shandong‑based drone manufacturer welcomed buyers from 30+ countries, with over 50 strong leads. One buyer, after seeing load and wind‑resistance demonstrations, immediately confirmed three sample units and even proposed becoming a regional distributor.

Display technology is another focal point of Phase 1, highlighting advances in color accuracy, energy efficiency, and overall visual performance. Developments in fine‑grained control, expanded color gamut, and reduced power consumption point to a clear trend toward immersive viewing experiences combined with sustainability gains.

The smart wearables zone underscores how intelligent devices are becoming key interfaces for human‑machine interaction. From real‑time language translation and adaptive noise cancellation to long‑term health monitoring and AI‑enabled eyewear, wearables are evolving from standalone products into integrated systems that support communication, well‑being, and productivity across daily and professional settings.

The service robots zone further illustrates how artificial intelligence is moving from conceptual exploration to large‑scale deployment. Advanced robots showcased across industrial, commercial, medical, and public‑service scenarios demonstrate growing autonomy, multi‑sensory perception, and closer human-robot collaboration.

By bringing emerging technologies into clearer focus through dedicated zones, the 139th Canton Fair is reinforcing its function as a platform where trade trends take shape, innovation meets application, and global buyers gain early insights into cutting-edge technologies.

For pre-registration, please click: https://buyer.cantonfair.org.cn/register/buyer/email?source_type=16

Photo – https://mma.prnewswire.com/media/2963958/1.jpg

View original content:https://www.prnewswire.co.uk/news-releases/phase-1-of-139th-canton-fair-introduces-new-dedicated-product-zones-as-emerging-technologies-take-center-stage-302751520.html

Continue Reading

Technology

OZMOSI Announces Strategic Partnership with Planview to Advance AI-Driven Planning in Pharmaceutical R&D

Published

on

By

By combining structured clinical intelligence with AI-driven portfolio planning, the partnership gives pharmaceutical teams a faster, clearer way to make high-stakes R&D decisions

SPRING LAKE HEIGHTS, N.J., April 23, 2026 /PRNewswire/ — OZMOSI, a leading provider of structured pharmaceutical development intelligence, today announced a strategic partnership with Planview, the leading AI-powered end-to-end platform for Strategic Portfolio Management (SPM) and Digital Product Delivery (DPD).

By integrating OZMOSI’s machine-readable clinical datasets directly into Planview’s AI-driven portfolio planning platform, external scientific data is now connected to internal R&D planning in one system,  helping pharmaceutical organizations better predict market shifts, prioritize R&D investments, and make faster, more confident decisions.

This integration brings external clinical reality into internal R&D decision-making, so teams can plan based on what’s actually happening, not just on what they hope will happen.

The two organizations combine deep expertise in complementary areas, united by a shared focus on improving the quality and usability of data for strategic decision-making. OZMOSI provides structured, machine-readable intelligence across clinical trials, drug development programs, regulatory activity, and scientific literature, built on a consistent taxonomy that standardizes how data is connected and understood. Planview’s platform enables organizations to model complex investment scenarios, align initiatives with corporate strategy, and optimize resource allocation.

Together, these capabilities give teams a clearer, more complete view of the R&D landscape, grounded in clean, standardized data and strengthened by AI-driven analysis.

“AI is only as powerful as the data that fuels it,” said Beau Bush, President and Founder of OZMOSI. “Pharmaceutical organizations have no shortage of data, but too often it’s fragmented, inconsistent, and difficult to operationalize. By bringing OZMOSI’s structured data foundation together with Planview’s AI-driven planning capabilities, we’re enabling teams to move beyond disconnected analysis and toward truly integrated, forward-looking decision-making.”

“Strategic planning in pharmaceutical R&D is becoming increasingly dependent on advanced analytics and AI,” said  Louise Allen, Chief Product Officer at Planview. “Integrating OZMOSI’s clinical intelligence into Planview’s platform enables pharmaceutical leaders to make better decisions by combining trusted external data with AI-driven planning

OZMOSI’s dataset spans more than 800,000 clinical trials, over 35,000 drugs, and 4,000 diseases and conditions. It brings together insights from clinical trial registries, regulatory filings, scientific literature, company disclosures, and industry announcements into a unified, structured dataset.

When integrated into Planview’s platform, this intelligence enables pharmaceutical and biotech organizations to evaluate competitive landscapes, identify emerging clinical trends, and simulate portfolio outcomes with unprecedented precision.

Together, OZMOSI and Planview are redefining how pharmaceutical organizations approach R&D strategy, ensuring that investment decisions are guided by accurate, standardized, and AI-ready data. By combining internal portfolio visibility with a continuously updated external view of the market, the partnership helps leaders not only understand what they have, but what to do next.

About OZMOSI

Founded in 2013, OZMOSI specializes in transforming complex pharmaceutical R&D intelligence into structured, machine-readable data. The company provides the foundation needed for accurate competitive analysis, product forecasting, and portfolio strategy. Through its proprietary taxonomy and semantic layer, OZMOSI connects fragmented data across the pharmaceutical ecosystem, enabling faster, more confident decision-making for global pharma, biotech, and investment teams.

Based in Spring Lake Heights, New Jersey, OZMOSI is focused on making pharmaceutical intelligence clear, usable, and ready for the future of AI-driven strategy. Learn more at www.ozmosi.com.

About Planview

Planview is the leading end-to-end platform for Strategic Portfolio Management (SPM) and Digital Product Delivery (DPD), powered by advanced AI capabilities that give business and technology leaders the strategic foresight to prioritize investments and initiatives, make plans real within constraints, and pivot with certainty when things change. Our AI-driven connected platform of solutions underpins the business and digital transformations of more than 3,000 customers and 3.1 million users globally. Headquartered in Austin, Texas, Planview has over 1,500 employees worldwide. Learn more at www.planview.com.

View original content to download multimedia:https://www.prnewswire.com/news-releases/ozmosi-announces-strategic-partnership-with-planview-to-advance-ai-driven-planning-in-pharmaceutical-rd-302750944.html

SOURCE Ozmosi Company

Continue Reading

Trending