Automatically translated.View original post

The Bybit team used AI to monitor the Amos malware release campaign.

The Bybit team used AI to detect Amos malware release campaigns until penetrating with reverse engineering methods.

Since Claude Code became the point of the source code being leaked, this artificial intelligence tool has been impersonated for the release of a lot of malware, but this time the malware that claims the AI name is about to be penetrated by another AI.

According to a report by the PR Newswire website, the Security Operations Center (SOC) of the famous Crypto Curren C (Exchange) trading provider website Bybit has brought in AI tools to monitor the AMOS malware release campaign, a malware type that steals data from the victim's machine, or an Infostealer that is headed to attack users of the macOS operating system. The use of AI tools to monitor the malware campaign is called "Re-Engineering," which can reach the infrastructure of the C2 control system. Command and Control, File Signature, Behavior Pattern, Malware Lifecycle, Intrusion Indicators (IOC) are all achieved within 40 minutes, shortening the traditional monitoring period by at least 6 to 8 hours. Bybit says that the new system allows teams to deal with intrusions from the wrong to 70% more sensitive than traditional ones.

For this round of AMOS malware distribution campaigns, Bybit has revealed that hackers have used a search poisoning method, SEO Poisoning, that causes those searching for Claude Code to find fake websites of hackers as the top of their search. In the fake website, there are many decorations that make them look credible, such as documents about AI tools similar to real websites, to lure victims into downloading fake application files that act as drippers. This leads to 2-step embedding of malware.

First, the Mach-O file format dropper runs osascript scripts to embed Infostealer malware like Amos (sometimes Banshee) on the machine, followed by multi-phase Obfuscation to steal important data such as passwords, codes saved on macOS Keychain, Telegram chat application access, VPN usage profile (Virtual Private Network), and Cryptokerrency wallet (Wallet). This malware can steal wallet data. It works as an extension of up to 250 web browsers.

The second step is to release another payload file, a backdoor type of malware written in C + + language that comes with a high level of detecting ability, including a system to detect if the malware is running on Sandbox Detection and Encryption. In part of the Runtime settings of the malware, this malware creates its own persistence on the system at any time, and then makes contact with the HTTP protocol, allowing hackers to remotely control the system. Yeah.

# Trending # Lemon 8 Howtoo # lemon 8 diary # bybit # freedomhack

1 day agoEdited to

... Read moreประสบการณ์ในการใช้ AI เพื่อตรวจจับและวิเคราะห์มัลแวร์แบบละเอียดนั้นกลายเป็นเรื่องที่ไม่น่าเชื่อว่าจะทำได้รวดเร็วและแม่นยำขนาดนี้ เมื่อ Bybit นำ AI มาใช้วิเคราะห์แคมเปญปล่อยมัลแวร์ Amos พวกเขาสามารถเจาะลึกถึงโครงสร้างพื้นฐานของมัลแวร์ เช่น ระบบควบคุม C2, File Signature และพฤติกรรมของมัลแวร์ ได้ภายในเวลาเพียง 40 นาที ซึ่งถือว่าเร็วกว่าเทคนิคการวิเคราะห์แบบดั้งเดิมที่ใช้เวลานานหลายชั่วโมงมาก สิ่งที่น่าสนใจคือเทคนิค SEO Poisoning ที่แฮกเกอร์ใช้ในการล่อเหยื่อ โดยปลอมแปลงเว็บไซต์ให้เหมือนของจริง ชื่อ Claude Code แล้วใช้กลยุทธ์นี้เพื่อหลอกให้คนดาวน์โหลดมัลแวร์ Dropper ที่เป็นจุดเริ่มต้นของการฝังมัลแวร์ Amos หรือบางครั้งก็ Banshee ลงเครื่อง macOS หลังจากนั้นมัลแวร์จะซ่อนตัวด้วยวิธี Obfuscation แบบหลายชั้น เพื่อขโมยข้อมูลสำคัญ ตั้งแต่รหัสผ่านใน Keychain, Session Telegram, โปรไฟล์ VPN ไปจนถึงข้อมูลกระเป๋าเงินคริปโตที่อยู่ในส่วนเสริมของเบราว์เซอร์ได้ถึง 250 ตัว แคมเปญนี้ยังใช้มัลแวร์ประเภท Backdoor เขียนด้วย C++ ซึ่งมีความสามารถในการหลบเลี่ยงระบบ Sandbox และทำให้มันทนทานสามารถเชื่อมต่อและควบคุมระยะไกลได้อย่างต่อเนื่อง สิ่งนี้สะท้อนให้เห็นว่าเทคโนโลยี AI สามารถเป็นได้ทั้งเครื่องมือในการโจมตีและการป้องกัน หากผู้ใช้งานทั่วไปและองค์กรต่าง ๆ เริ่มนำ AI มาช่วยวิเคราะห์ความปลอดภัยไซเบอร์อย่างจริงจัง จะสามารถลดความเสี่ยงและรับมือกับภัยคุกคามได้ดีขึ้น ดังนั้น การเพิ่มความรู้เรื่อง AI ในการรักษาความปลอดภัยและการอัพเดตมาตรการป้องกันอย่างสม่ำเสมอเป็นสิ่งจำเป็นสำหรับผู้ใช้ทุกคนในยุคดิจิทัลนี้

Related posts

It's no secret that Karol G just slayed the #Grammys #Glambot . #AwardsSeason
user6854050772614

user6854050772614

11 likes

All in one software that actually assists you 💗🥹 try it now on https://qclawsg.qq #qclaw #ai #aiassistant #explore #viral
Peggy Tan 🍒

Peggy Tan 🍒

0 likes

ENTER TO WIN THIS 27 INCH 1440P Monitor curtosey of @Newegg, Inc. & @AsRock USA ~Follow me @Dominionvrc & @ASRock Phantom Gaming ~Like this post ~Comment & Tag 2 people Winner will be announced next Friday!!! ✌🏾✌🏾✌🏾 #vrchat #gaming #giveaway #vrc #tiktoklive
D O M I N I O N V R C

D O M I N I O N V R C

4 likes

Top NCLEX exemplars Episode 82- osteoarthritis #EduTok #TikTokLearningCampaign #fyp #nurses #osteoarthritis
Codebluebabe

Codebluebabe

1 like

No interview required and pick your own hours! #workfromhome #wfhjobs #workathomejobs #remotejobs #wfhjobshiringimmediately
Arialle Tate

Arialle Tate

27 likes

Explain the film from a first-person perspective #worldcup #movie #dallatteampart #edit #TikTokCampaign
Qava Betepina

Qava Betepina

107 likes

A person smiling with eyes closed, sitting in front of two computer monitors, with the text "how i got my remote job" overlaid.
A MacBook Air displaying the Indeed.com website with job listings, accompanied by the overlaid text "ditch indeed ❌".
A MacBook Air displaying the LinkedIn login page, with the overlaid text "say yes to linkedin! ✅".
how i got my REMOTE job✨
many people ask me how i got my remote job at 20 + because i don’t like gatekeeping over here, it’s time i share!! ⬇️ DITCH INDEED❌ — when i was searching for a remote job, my first thought was to go to indeed. and boy, was that a mistake! it’s so easy to make an application on there for “remot
m a l e n a

m a l e n a

6554 likes

Developing a career in cybersecurity
Hey All! 👋 Want to stay safe online and protect your data? Cybersecurity knowledge is essential. It helps you secure your personal information and understand how to safeguard your digital footprint. Let’s dive into why it’s crucial! 💻🔒 Why Cybersecurity Matters Cybersecurity is about protecting
Meghana

Meghana

551 likes

New AI tool replaces marketing team
One tool drives traffic, optimizes, increases visibility, everything you need one tool. #ainews #aiupdate #aitool #aimarketing
bananas

bananas

0 likes

A young woman with long dark hair, wearing a pink satin shirt, smiles at the camera while sitting at a table. Overlay text reads: 'Tools and sites I use as a cybersecurity student to progress my skills and keep me interested in studying'.
A screenshot of 'The Hacker News' website, displaying various cybersecurity news articles from January 2025, including topics like vulnerabilities, malware, cyber espionage, and AI jailbreak methods. An ad for Zscaler and a banner for CIS Hardened Images are also visible.
A screenshot of the O'Reilly learning platform, showing various books and expert playlists related to AI, engineering, and data. Overlay text highlights the subscription cost ($50/month or $499/year) and its value for accessing books and live events.
Tools and sites I use as a cybersecurity student 🌸
#cybersecuritystudent #cybersecurity #techgirlie
LexiStudies

LexiStudies

107 likes

Top NCLEX medications episode 77-cryoprecipitate #cryoprecipitate #fyp #tiktoklearningcampaign #edutok #nursingstudent
Codebluebabe

Codebluebabe

2 likes

1 Language 5 accents ep.3
ข่าวต่างประเทศ (โดยสำเนียง) เดินทางมาถึง ep.3 โดยที่การเมืองไทยเข้มข้นและน่าติดตามกว่าการดูซีรี่ย์เกาหลีไปแล้ว #คันซอคฮี #คังแทฮี #โซฟาเลีย #ภาษา #ไทย #สำเนียง #เกาหลี #ฝรั่งเศส #จีน #อังกฤษ #language #accent #thai #english #korean #french #chinese #fyp
mamamanisorn

mamamanisorn

3 likes

ERROR ERROR ERROR ERROR ERROR
🔺️!!!Flashy!!!🔺️ Um guys... Something is definitely wrong with my tablet 😬😨 #rewritesonic #malware #sonicexe #sonicthehedgehog #sonicfanart
EmK & Fidgi

EmK & Fidgi

2 likes

A flat lay image featuring a pink notebook, gold heart-shaped dish with paperclips, and a gold pen, alongside a keyboard and pink flowers. The text overlay reads "5 FREE ONLINE CERTIFICATIONS to Boost YOUR RESUME."
The image displays the logo for "Learning How to Learn" with a brain and sun icon. Text describes this Coursera course from UC San Diego, focusing on improving learning techniques, memory, and study strategies.
The image shows the "Learn SQL" logo. Text describes Codecademy's free SQL course, emphasizing its importance for data analysis, database management, querying, creating tables, and manipulating data.
5 Free Online Certifications to Boost Your Resume
Hi, lemons! In today's competitive job market, having a standout resume is crucial. Employers seek candidates with not only relevant experience but also a commitment to continuous learning. Fortunately, the digital age offers a wealth of free online certifications that can enhance your skill se
Lifestyle Babe

Lifestyle Babe

743 likes

This role I got to play parallels the story of AB Hernandez — a young trans girl just looking for belonging and a chance to play with her friends⚽️🏐🏉 So honored to bring Cheyenne to life for Hidden Canyons — directed by the one & only @navamau ✨ Meet the dream team: 👧🏽 Cheyenne: (Ur’s Tru
Quei Tann

Quei Tann

1 like

Top NCLEX medications Episode 86 - propofol #fyp #LearnOnTikTok #TikTokLearningCampaign #icu #nurses
Codebluebabe

Codebluebabe

2 likes

Iran RECEIVES 500 Hwasong-18 ICBMs From North Korea, Israel DOOMED, U.S. TREMBLES #breakingnews #news #fyp #iran #us
BBC News

BBC News

0 likes

If you like Notion, you might like…
[Save this to your useful tools folder] If you use Notion a lot, you might find these tools interesting as well: Milanote is a versatile online tool designed for visual organization and collaboration. It provides a flexible platform for users to gather ideas, plan projects, and organize infor
Reeda ✨

Reeda ✨

340 likes

3 cybersecurity jobs that pay well
1. Security Analyst - What They Do: Monitor networks for vulnerabilities, investigate breaches, and implement security measures. - How to Start: - Obtain certifications like CompTIA Security+ or CySA+. - Gain experience with tools like SIEM (e.g., Splunk). - Start in an I
vedha | career tips (tech) 👩‍

vedha | career tips (tech) 👩‍

633 likes

Back Up Outlook Emails to an External Hard Drive
Need to back up your Outlook emails to an external hard drive? Here are 2 simple methods to help you out. Download AOMEI Backupper and give it a try! #backup #outlook #externalharddrive
SmoothTechie

SmoothTechie

1 like

Also thank you for hangin with me and the nerds today 🌻 #chikorita #twitch #pokemonlegendsza
Diamiour

Diamiour

2 likes

#batman is not the world’s greatest detective in fact he’s like the latest detective to find the guild. The world’s greatest detective is #detectivechimp #dccomics
Dan!

Dan!

3 likes

How to turn $65 into $5000 with this simple idea
Remember, investing in crowdfunding is not a guaranteed way to turn $65 into $5000. It requires careful research, risk management, and a long-term perspective. Always be prepared to lose some or all of your investment, and only invest money that you can afford to lose. Don't forget to Commen
Investingashley

Investingashley

88 likes

Files Copied to USB Drive Disappear? Lets Recover
Copied files to your USB drive, then they vanished? This issue is often caused by hidden files, unsafe ejection, corruption, or failing flash storage. This guide shows how to reveal hidden files, repair USB errors, and recover missing data safely before it gets overwritten. #usb #datarecovery
XanthusTechCore

XanthusTechCore

3 likes

A Ben 10 gym audio for you. #fyp #gym #ben10 #ben10omniverse #audio
IzzyywiththeZ

IzzyywiththeZ

0 likes

How to join Sbeauti TTO program
SBEAUTIBRA

SBEAUTIBRA

2 likes

You need TikTok ?
Here is how you can download TikTok if you need help with and apple phone just ask me I can help with Apple phone you need to change your region on the Apple Pay store
Ali

Ali

10 likes

I just won something!🫨
#winning #winner #prize #Lemon8Diary #gamergirl #participating #Lemon8 #lemon8diarychallenge I can’t believe it :0
Nany

Nany

51 likes

Perfect stand for IPad or small monitor!
https://www.amazon.com/dp/B0BTDHQJ6X?ref=t_ac_view_request_product_image&campaignId=amzn1.campaign.1HVV5EMFRF268&linkCode=tr1&tag=mirandabulloc-20&linkId=amzn1.campaign.1HVV5EMFRF268_1776879540077 #ad #lisen #amazonfinds #amazon
mandib

mandib

0 likes

Let me know any questions I’ll be doing more videos FOLLOW AND LIKE ❤️ #sahm #pregnancy #momcozybabyregistry #25weekspregnant #babypr #emailingbabycompanies #emailingbrands #pr #mominfluencer #pregnancytiktok #babybrands #brandcollabs #itzyritzy #momcozy #legendairymilk @Legenda
Vanessa

Vanessa

2 likes

Why I switched to taking notes on my iPad
I used to love writing in notebooks, but after switching to my iPad, I can confidently say I’m never going back! Here’s why: ✨ Cuter Notes – Let’s be real…aesthetic notes make studying more enjoyable! I can use custom colors, cute stickers, and different handwriting styles to make my notes visua
Rebecca R.

Rebecca R.

263 likes

+it’s less than 80$✨❗️LINK for this item in my bio❗️
Details⬇️: This flip phone smartphone with a flip keyboard design, offering both the convenience of a traditional keypad and the functionality of a modern touchscreen device. With 4GB of internal storage, you'll have plenty of space for apps, photos, and more. The compact 3.5" displa
Atlas

Atlas

443 likes

dog leak top secret intelligence
#CapCut
lukatalks

lukatalks

2 likes

Elite Hacker Destroyed His Empire By Forgetting On
Bro, I really forgot to use a VPN 💀 #hacker #cybercrime #fail #tech #arrestedstupidly
arrestedstupidly

arrestedstupidly

1 like

#fy #fyp #fypシ゚viral #horrorgame Just tired of getting jumped😭, go subscribe to my YT channel.
dis-MALware

dis-MALware

3 likes

Pass the Phone challenge with antibiotics 😭 Amoxicillin (Amoxil) Vancomycin (Vancocin) Doxycycline Ciprofloxacin (Cipro) Clindamycin Azithromycin (Z-Pack) C diff antibiotic resistance NCLEX 💊 #fyp #EduTok #TikTokLearningCampaign #nurses #clindamycin
Codebluebabe

Codebluebabe

2 likes

Smart Slider 3 Pro Used In Supply Chain Attack
Attackers compromised the update infrastructure for Smart Slider 3 Pro and pushed a weaponized build - version 3.5.1.35 - through the official update channel. The compromised version was live for approximately six hours before it was caught. Only the Pro version was affected, but any site that inst
Wordfence

Wordfence

1 like

SATURDAY | 2 MAY 2026 | Cybersecurity Report
The digital frontlines just got a lot more dangerous. Today on Cyber F.M., host Arias Thomas breaks down the industrialization of cybercrime and the collapse of the software supply chain. If you think your "secure" tools are safe, think again. Inside Today’s Broadcast: 🏮 The Paperclip
Cyber F.M.

Cyber F.M.

3 likes

30+ WordPress Plugins Used In Supply Chain Attack
30+ WordPress Plugins Used In Supply Chain Attack | Wordfence Security News Clip | April 13, 2026 A buyer acquired more than 30 WordPress plugins through the Flippa marketplace after purchasing the Essential Plugin portfolio for a six-figure sum. The buyer's first code commit was a backdoor
Wordfence

Wordfence

1 like

A person with long dark hair and a straw hat walks through a sunny public square. Overlay text reads "CYBERSECURITY CAREER Tips to get started," introducing advice for a career in cybersecurity.
A person in a white dress walks on a path next to green bushes. Overlay text advises to "Build a Strong Technical Foundation" by learning networking basics, operating systems, and scripting languages.
People walk across a street with benches and trees in the background. Overlay text suggests to "Get Hands-On Experience" through CTF competitions, cybersecurity challenges, and setting up a home lab.
Tips for pursuing a career in cybersecurity
1. Build a Strong Technical Foundation A solid understanding of systems, networks, and programming is essential for identifying and mitigating security threats. • Learn networking basics (e.g., TCP/IP, firewalls, VPNs). • Gain familiarity with operating systems (Windows, Linux)
vedha | career tips (tech) 👩‍

vedha | career tips (tech) 👩‍

132 likes

See more