Fake Claude desktop app spreads crypto-stealing malware
RevStealer targets more than 50 crypto wallets alongside browser passwords, cookies, messaging data and selected documents.
A fake Claude desktop application is being used to distribute RevStealer, a Windows malware strain designed to steal cryptocurrency, passwords, browser data, and other sensitive information. According to cybersecurity company Morphisec, RevStealer was previously spread via GitHub repositories and game-cheat-themed websites, but the most notable infection vector is the counterfeit "Claude Opus 5 Free Desktop" project.
This project falsely markets itself as a free access point to AI developer Anthropic, when in reality it downloads and installs the malicious software. RevStealer is engineered to leave minimal traces, scanning browser databases, cookies, password managers, VPN and remote access configurations, messaging apps, screenshots, and selected documents.
Additionally, the malware targets over 50 cryptocurrency wallets, determining if the infected machine resembles a typical user device by examining memory, processor cores, hostname, username, and graphics hardware. It also checks for debugging delays commonly found in malware analysis settings. If the system appears suspicious, RevStealer aborts further infection attempts.
However, if the checks pass, the malicious payload is decrypted, saved under a randomized name, and silently executed. This malware follows the discovery of OkoBot, another malware framework targeting cryptocurrency investors, which can extract wallet files, browser data, user credentials, inject malicious extensions, and capture application windows to steal assets.
Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.