Breaking
TRFenerbahçe and Beşiktaş will play derby for the 60th time in KadıköyESThe transfer market enters its final hours with pending operations, including the future of Julián ÁlvarezRUThe second tournament of the Real American Freestyle league outside the USA will be held in MoscowESThe Government of the Generalitat presents the events of the Day of September 11 on the occasion of the 50th anniversary of its recoveryFRTrump announces historic oil deal with Venezuela, Mélenchon defends his debt cancellation plan, von der Leyen calls for investing European savingsFRFatal towed buoy accident in Saint-Cyprien: two dead and one seriously injuredRUIn Moscow, due to heavy rain, it is recommended to abandon personal transportDEHackers blackmail Berlin with a ransom demand of two million eurosFRRacist attack after OL-Le Havre: Meriem Bouchedda and her partner victims of violenceVNFilipino bride wades through floods to get married in flooded waterTRFenerbahçe and Beşiktaş will play derby for the 60th time in KadıköyESThe transfer market enters its final hours with pending operations, including the future of Julián ÁlvarezRUThe second tournament of the Real American Freestyle league outside the USA will be held in MoscowESThe Government of the Generalitat presents the events of the Day of September 11 on the occasion of the 50th anniversary of its recoveryFRTrump announces historic oil deal with Venezuela, Mélenchon defends his debt cancellation plan, von der Leyen calls for investing European savingsFRFatal towed buoy accident in Saint-Cyprien: two dead and one seriously injuredRUIn Moscow, due to heavy rain, it is recommended to abandon personal transportDEHackers blackmail Berlin with a ransom demand of two million eurosFRRacist attack after OL-Le Havre: Meriem Bouchedda and her partner victims of violenceVNFilipino bride wades through floods to get married in flooded water
BackFake Claude Desktop App Distributes RevStealer Malware Targeting Crypto and Data
Fake Claude Desktop App Distributes RevStealer Malware Targeting Crypto and Data
Developing
Cointelegraph48 minutes agoTech1 min read

Fake Claude Desktop App Distributes RevStealer Malware Targeting Crypto and Data

Quick Look

  • Cybersecurity firm Morphisec reports that a fake 'Claude Opus 5 Free Desktop' application is distributing RevStealer malware, which steals cryptocurrency, passwords, and browser data by mimicking legitimate user behavior to evade detection.
  • The malware also targets over 50 crypto wallets and system settings, following Kaspersky's discovery of OkoBot, another crypto-focused malware framework.

AI-generated summary

Why It Matters

RevStealer is a Windows malware strain designed to steal cryptocurrency, passwords, and browser data by evading detection through user-like behavior checks. It was previously distributed via GitHub and game-cheat sites before shifting to a fake Claude desktop app impersonating Anthropic.

Font size

A fake Claude desktop application is reportedly being used to distribute RevStealer, a Windows malware strain built to steal crypto, password and browser data.

According to a Monday report by cybersecurity company Morphisec, RevStealer was previously distributed through GitHub repositories and game-cheat-themed sites but the most notable is a fake “Claude Opus 5 Free Desktop” project that impersonates AI developer Anthropic and promises free access to Claude.

The researchers noted that the malware is designed to leave few traces and searches browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots and selected documents. RevStealer also targets over 50 cryptocurrency wallets.

The malware checks whether the machine looks like a real user device before unlocking its malicious payload, looking at available memory, the number of processor cores, hostname, username and graphics hardware. It also monitors for the debugging delays typical of malware analysis environment.

If RevStealer detects anything out of the ordinary, it does not move on to the next stages of infection and malicious activity. If the system passes those checks, the payload is decrypted, stored under a random name and covertly executed.

The report follows the discovery by Russian cybersecurity company Kaspersky of a new malware framework targeting cryptocurrency investors called OkoBot, which can harvest crypto wallet files, browser data and user credentials, inject malicious extensions and capture wallet application windows to steal assets.

What to Watch

AI outlook — possibilities, not facts

  • Increased reports of RevStealer infections as the fake Claude app continues to distribute

    Likely · Within weeks

  • Cybersecurity firms will release detection signatures for RevStealer and OkoBot

    Very likely · Within days

Open Questions

  • How many systems have been infected by RevStealer so far?
  • Is the fake Claude app still active on distribution platforms?
  • What specific cryptocurrency wallets are targeted by RevStealer?
  • Are there any known attribution links to threat actors behind RevStealer or OkoBot?

Related Topics

This article was originally published by Cointelegraph.

Related Stories

Mystery Bitcoin Wallet Moves $1 Million Through Custodian Before Burning Coins
Developing·yesterday

Mystery Bitcoin Wallet Moves $1 Million Through Custodian Before Burning Coins

A Bitcoin wallet dormant for 12 years moved $1 million through a large crypto custodian in March, received nearly the same amount back three weeks later, and then deliberately burned the Bitcoin in May. Blockchain analysis links five wallets to the same early Bitcoin holder, possibly an Mt. Gox adopter, but the motive for the round-trip transaction and subsequent destruction remains unknown.

Cointelegraph
3 min read
More on this topicclaude