Bybit’s AI‑Driven SOC Uncovers Sophisticated macOS Malware Campaign Targeting Claude Code Searchers

  • News
  • April 22, 2026

Bybit’s AI‑driven SOC has revealed a sophisticated macOS malware campaign that hijacks users searching for Anthropic’s Claude Code, marking one of the first public disclosures of an AI‑assisted threat vector by a major cryptocurrency exchange.

The Discovery

In March 2026, Bybit’s SOC detected a multi‑stage infection chain aimed at macOS devices. The attackers leveraged SEO poisoning to push a malicious domain to the top of Google search results for “Claude Code,” an AI‑powered development tool. When users clicked the spoofed link, they were led to a counterfeit installation page that mimicked official documentation, initiating a two‑phase attack.

The first payload, a Mach‑O dropper, deployed an osascript‑based infostealer reminiscent of the AMOS and Banshee families. It harvested browser credentials, macOS Keychain entries, Telegram sessions, VPN profiles, and cryptocurrency wallet data. Bybit analysts noted that the malware specifically targeted over 250 browser‑based wallet extensions and several desktop wallet applications.

A second‑stage C++ backdoor followed, featuring sandbox detection, encrypted runtime configurations, and persistence via system agents. It communicated with command‑and‑control (C2) servers through intermittent HTTP polling, allowing attackers continuous remote control without raising obvious network flags.

AI‑Assisted Analysis Accelerates Response

Bybit credits its AI‑enhanced workflow for compressing a typical six‑to‑eight‑hour deep‑inspection window into under 40 minutes. Machine‑learning models flagged behavioral similarities during triage, while AI‑driven reverse engineering mapped control‑flow and extracted indicators of compromise (IOCs) at unprecedented speed. The platform then auto‑generated detection signatures and endpoint rules, which analysts reviewed before deployment.

According to the SOC lead, David Zong, “Our AI‑assisted SOC allows us to move from detection to full kill‑chain visibility within a single operational window… AI handling the heavy lifting and our analysts providing judgment and validation.” Bybit estimates that AI‑generated reporting drafts cut turnaround time by roughly 70 %.

Why It Matters for the FinTech Ecosystem

The campaign underscores a growing trend: threat actors targeting developers through manipulated search results, especially as AI tools become mainstream. For fintech firms, developers often hold privileged access to code repositories, cloud infrastructure, and financial APIs—making them high‑value targets. Gartner predicts that AI‑driven attacks will increase by 30 % by 2027, while IDC reports 45 % of fintech organizations plan to boost AI security spend in the next two years.

By exposing the attack vector, Bybit provides the broader industry with actionable intelligence that can be integrated into existing security stacks, from SIEMs to XDR platforms. Enterprises that rely on open banking APIs or embedded finance solutions can now incorporate the disclosed IOCs into their threat‑hunts, reducing the risk of credential theft that could compromise payment pipelines or customer data.

Comparison with Competing Solutions

Traditional SOCs often rely on manual reverse engineering, which can extend analysis cycles to days. By contrast, Bybit’s AI‑augmented approach mirrors capabilities seen in leading cloud security providers like Microsoft Defender for Endpoint and Amazon GuardDuty, but with a focus on crypto‑specific threat landscapes. While those platforms excel at detecting generic malware, Bybit’s niche expertise in cryptocurrency wallet targeting fills a critical gap for fintech firms that handle digital assets.

Implications for Enterprise Marketing Teams

Security breaches that expose wallet credentials can erode consumer trust, directly impacting brand perception and acquisition costs. Marketing teams must now collaborate closely with security ops to communicate risk mitigation strategies transparently. By integrating AI‑generated security insights into customer communications, enterprises can demonstrate proactive defense, a differentiator in a competitive fintech market.

SEO Poisoning as an Attack Vector

The attackers’ use of SEO manipulation highlights the importance of monitoring search engine rankings for brand‑related queries. SEO poisoning enabled attackers to hijack searches for “Claude Code,” exposing a new attack surface for developers.

AI‑Powered Threat Hunting

AI reduces the time from detection to remediation, a capability increasingly essential for high‑velocity fintech environments.

Future Outlook: AI vs. AI

Bybit warns of an “AI war,” where defensive AI tools will be essential to counter increasingly sophisticated AI‑generated attacks.

Market Landscape

The fintech security market is rapidly evolving. According to Forrester, 38 % of financial services firms plan to adopt AI‑based threat detection by 2025. Cloud providers such as Google Cloud and Microsoft Azure are expanding AI security services, while specialized players like CrowdStrike and SentinelOne focus on endpoint protection. Bybit’s public disclosure adds a rare crypto‑exchange perspective, offering a data point that bridges traditional financial security and emerging digital‑asset threats.

Top Insights

  • Bybit’s AI‑enhanced SOC cut deep‑inspection time from up to eight hours to under 40 minutes, accelerating threat response.
  • SEO poisoning enabled attackers to hijack searches for “Claude Code,” exposing a new attack surface for developers.
  • The campaign targeted over 250 browser‑based crypto wallet extensions, highlighting the vulnerability of embedded finance tools.
  • AI‑driven analysis allowed same‑day creation and deployment of detection signatures, reducing potential breach windows.
  • FinTech ecosystem must integrate AI‑generated IOCs into their security stacks to guard against credential‑theft attacks that can disrupt payment flows.
  • Digital finance organizations benefit from proactive threat intelligence to maintain trust.

Get in touch with our fintech expert

Related Posts

  • News
  • September 10, 2026
  • 40 views
o15 Exits $31M Simplify Compliance Credit Facility

o15 Capital Partners has completed the exit of a $31 million senior secured credit facility provided to Simplify Compliance Holdings, following the sale of Simplify’s datacenterHawk business to S&P Global.…

  • News
  • September 10, 2026
  • 36 views
Blue Ocean Closes $1.3B Fund for Maritime Finance

Blue Ocean, the maritime finance investment platform managed by EnTrust Global, has closed its fourth rated-notes fund with $1.3 billion in commitments, giving primarily U.S. insurance investors a capital-efficient route…

Leave a Reply

Your email address will not be published. Required fields are marked *

You Missed

o15 Exits $31M Simplify Compliance Credit Facility

  • September 10, 2026
o15 Exits $31M Simplify Compliance Credit Facility

Blue Ocean Closes $1.3B Fund for Maritime Finance

  • September 10, 2026
Blue Ocean Closes $1.3B Fund for Maritime Finance

MVB and Velocity Bring Stablecoins Into Visa Direct

  • September 10, 2026
MVB and Velocity Bring Stablecoins Into Visa Direct

Bybit AI Turns Crypto Trading Into a Chat Experience

  • September 10, 2026
Bybit AI Turns Crypto Trading Into a Chat Experience

Alkami Study Finds Digital Banking Is Now the Relationship Layer

  • September 10, 2026
Alkami Study Finds Digital Banking Is Now the Relationship Layer

Whalet Puts AI at the Center of Agentic Commerce Payments

  • September 10, 2026
Whalet Puts AI at the Center of Agentic Commerce Payments

Get the latest insights and updates

delivered to your inbox.

Newsletter Signup

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

Global FinTech Edge will use the information you provide on this form to be in touch with you and to provide updates and marketing.