Fake Claude Desktop App Distributes RevStealer Malware Targeting Crypto and Data
Quick Look
- Cybersecurity firm Morphisec reports that a fake 'Claude Opus 5 Free Desktop' application is distributing RevStealer malware, which steals cryptocurrency, passwords, and browser data by mimicking legitimate user behavior to evade detection.
- The malware also targets over 50 crypto wallets and system settings, following Kaspersky's discovery of OkoBot, another crypto-focused malware framework.
AI-generated summary
Why It Matters
RevStealer is a Windows malware strain designed to steal cryptocurrency, passwords, and browser data by evading detection through user-like behavior checks. It was previously distributed via GitHub and game-cheat sites before shifting to a fake Claude desktop app impersonating Anthropic.
A fake Claude desktop application is reportedly being used to distribute RevStealer, a Windows malware strain built to steal crypto, password and browser data.
According to a Monday report by cybersecurity company Morphisec, RevStealer was previously distributed through GitHub repositories and game-cheat-themed sites but the most notable is a fake “Claude Opus 5 Free Desktop” project that impersonates AI developer Anthropic and promises free access to Claude.
The researchers noted that the malware is designed to leave few traces and searches browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots and selected documents. RevStealer also targets over 50 cryptocurrency wallets.
The malware checks whether the machine looks like a real user device before unlocking its malicious payload, looking at available memory, the number of processor cores, hostname, username and graphics hardware. It also monitors for the debugging delays typical of malware analysis environment.
If RevStealer detects anything out of the ordinary, it does not move on to the next stages of infection and malicious activity. If the system passes those checks, the payload is decrypted, stored under a random name and covertly executed.
The report follows the discovery by Russian cybersecurity company Kaspersky of a new malware framework targeting cryptocurrency investors called OkoBot, which can harvest crypto wallet files, browser data and user credentials, inject malicious extensions and capture wallet application windows to steal assets.
What to Watch
AI outlook — possibilities, not facts
Increased reports of RevStealer infections as the fake Claude app continues to distribute
Likely · Within weeks
Cybersecurity firms will release detection signatures for RevStealer and OkoBot
Very likely · Within days
Open Questions
- How many systems have been infected by RevStealer so far?
- Is the fake Claude app still active on distribution platforms?
- What specific cryptocurrency wallets are targeted by RevStealer?
- Are there any known attribution links to threat actors behind RevStealer or OkoBot?







