NewsCryptoFake Claude Desktop App Used to Distribute RevStealer Crypto-Stealing Malware

Fake Claude Desktop App Used to Distribute RevStealer Crypto-Stealing Malware

Author: Cointelegraph·

Key Takeaways

  • •Morphisec reported that a counterfeit "Claude Opus 5 Free Desktop" app impersonating Anthropic distributes the RevStealer Windows malware.
  • •RevStealer steals browser data, passwords, messaging data, screenshots, and targets more than 50 cryptocurrency wallets.
  • •The malware performs anti-analysis checks on system memory, processor cores, hostname, username, and graphics hardware before executing its payload.
  • •The findings follow Kaspersky's discovery of OkoBot, a malware framework that also targets cryptocurrency investors.
  • •Users can reduce risk by downloading software only from official vendor sites rather than third-party repositories or search-result links.
Fake Claude Desktop App Used to Distribute RevStealer Crypto-Stealing Malware

A counterfeit Claude desktop application is reportedly being used to distribute RevStealer, a Windows malware strain designed to steal cryptocurrency, password and browser data from infected machines.

According to a Monday report by cybersecurity firm Morphisec, RevStealer has previously been distributed through GitHub repositories and game-cheat-themed websites, but the most notable campaign involves a fake "Claude Opus 5 Free Desktop" project. The project impersonates Anthropic, the AI developer behind the Claude assistant, and promises users free access to the chatbot. The lure taps into strong demand for desktop versions of popular AI assistants, a pattern that has made AI-branded software a growing vehicle for social engineering, as victims are more likely to trust downloads that appear to come from well-known AI brands.

Morphisec's researchers noted that the malware is built to leave few traces on compromised systems. It searches browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots and selected documents. RevStealer also targets more than 50 cryptocurrency wallets. The breadth of that target list reflects how infostealers have become one of the most active malware categories in recent years, with stolen credentials and wallet data often harvested in bulk and sold or exploited by criminal groups.

Before unlocking its malicious payload, the malware checks whether the host machine looks like a genuine user device. It examines available memory, the number of processor cores, the hostname, the username and the graphics hardware. It also monitors for the debugging delays characteristic of malware analysis environments. Such anti-analysis checks are a common technique among modern malware families, used to frustrate automated sandboxing and researcher scrutiny before the payload runs.

If RevStealer detects anything out of the ordinary, it does not proceed to the next stages of infection and malicious activity. If the system passes these checks, the payload is decrypted, stored under a random name and covertly executed.

The findings follow the discovery by Russian cybersecurity company Kaspersky of a new malware framework targeting cryptocurrency investors, dubbed OkoBot. That framework can harvest crypto wallet files, browser data and user credentials, inject malicious extensions and capture wallet application windows in order to steal assets. The back-to-back discoveries point to continued criminal focus on crypto holders, and users can reduce exposure by downloading software only from official vendor sites rather than third-party repositories or search-result links.

Related: Microsoft warns users of 'Crypto Clipper' malware spread via USB drives