Bybit’s AI‑driven SOC has revealed a sophisticated macOS malware campaign that hijacks users searching for Anthropic’s Claude Code, marking one of the first public disclosures of an AI‑assisted threat vector by a major cryptocurrency exchange.
The Discovery
In March 2026, Bybit’s SOC detected a multi‑stage infection chain aimed at macOS devices. The attackers leveraged SEO poisoning to push a malicious domain to the top of Google search results for “Claude Code,” an AI‑powered development tool. When users clicked the spoofed link, they were led to a counterfeit installation page that mimicked official documentation, initiating a two‑phase attack.
The first payload, a Mach‑O dropper, deployed an osascript‑based infostealer reminiscent of the AMOS and Banshee families. It harvested browser credentials, macOS Keychain entries, Telegram sessions, VPN profiles, and cryptocurrency wallet data. Bybit analysts noted that the malware specifically targeted over 250 browser‑based wallet extensions and several desktop wallet applications.
A second‑stage C++ backdoor followed, featuring sandbox detection, encrypted runtime configurations, and persistence via system agents. It communicated with command‑and‑control (C2) servers through intermittent HTTP polling, allowing attackers continuous remote control without raising obvious network flags.
AI‑Assisted Analysis Accelerates Response
Bybit credits its AI‑enhanced workflow for compressing a typical six‑to‑eight‑hour deep‑inspection window into under 40 minutes. Machine‑learning models flagged behavioral similarities during triage, while AI‑driven reverse engineering mapped control‑flow and extracted indicators of compromise (IOCs) at unprecedented speed. The platform then auto‑generated detection signatures and endpoint rules, which analysts reviewed before deployment.
According to the SOC lead, David Zong, “Our AI‑assisted SOC allows us to move from detection to full kill‑chain visibility within a single operational window… AI handling the heavy lifting and our analysts providing judgment and validation.” Bybit estimates that AI‑generated reporting drafts cut turnaround time by roughly 70 %.
Why It Matters for the FinTech Ecosystem
The campaign underscores a growing trend: threat actors targeting developers through manipulated search results, especially as AI tools become mainstream. For fintech firms, developers often hold privileged access to code repositories, cloud infrastructure, and financial APIs—making them high‑value targets. Gartner predicts that AI‑driven attacks will increase by 30 % by 2027, while IDC reports 45 % of fintech organizations plan to boost AI security spend in the next two years.
By exposing the attack vector, Bybit provides the broader industry with actionable intelligence that can be integrated into existing security stacks, from SIEMs to XDR platforms. Enterprises that rely on open banking APIs or embedded finance solutions can now incorporate the disclosed IOCs into their threat‑hunts, reducing the risk of credential theft that could compromise payment pipelines or customer data.
Comparison with Competing Solutions
Traditional SOCs often rely on manual reverse engineering, which can extend analysis cycles to days. By contrast, Bybit’s AI‑augmented approach mirrors capabilities seen in leading cloud security providers like Microsoft Defender for Endpoint and Amazon GuardDuty, but with a focus on crypto‑specific threat landscapes. While those platforms excel at detecting generic malware, Bybit’s niche expertise in cryptocurrency wallet targeting fills a critical gap for fintech firms that handle digital assets.
Implications for Enterprise Marketing Teams
Security breaches that expose wallet credentials can erode consumer trust, directly impacting brand perception and acquisition costs. Marketing teams must now collaborate closely with security ops to communicate risk mitigation strategies transparently. By integrating AI‑generated security insights into customer communications, enterprises can demonstrate proactive defense, a differentiator in a competitive fintech market.
SEO Poisoning as an Attack Vector
The attackers’ use of SEO manipulation highlights the importance of monitoring search engine rankings for brand‑related queries. SEO poisoning enabled attackers to hijack searches for “Claude Code,” exposing a new attack surface for developers.
AI‑Powered Threat Hunting
AI reduces the time from detection to remediation, a capability increasingly essential for high‑velocity fintech environments.
Future Outlook: AI vs. AI
Bybit warns of an “AI war,” where defensive AI tools will be essential to counter increasingly sophisticated AI‑generated attacks.
Market Landscape
The fintech security market is rapidly evolving. According to Forrester, 38 % of financial services firms plan to adopt AI‑based threat detection by 2025. Cloud providers such as Google Cloud and Microsoft Azure are expanding AI security services, while specialized players like CrowdStrike and SentinelOne focus on endpoint protection. Bybit’s public disclosure adds a rare crypto‑exchange perspective, offering a data point that bridges traditional financial security and emerging digital‑asset threats.
Top Insights
- Bybit’s AI‑enhanced SOC cut deep‑inspection time from up to eight hours to under 40 minutes, accelerating threat response.
- SEO poisoning enabled attackers to hijack searches for “Claude Code,” exposing a new attack surface for developers.
- The campaign targeted over 250 browser‑based crypto wallet extensions, highlighting the vulnerability of embedded finance tools.
- AI‑driven analysis allowed same‑day creation and deployment of detection signatures, reducing potential breach windows.
- FinTech ecosystem must integrate AI‑generated IOCs into their security stacks to guard against credential‑theft attacks that can disrupt payment flows.
- Digital finance organizations benefit from proactive threat intelligence to maintain trust.
Get in touch with our fintech expert






