Fake Claude Desktop Apps Distribute RevStealer, Targeting 50+ Crypto Wallets

Fake Claude Desktop Apps Distribute RevStealer, Targeting 50+ Crypto Wallets

N
News Editor
2026-09-01 14:10:24
Fake Claude desktop apps are spreading RevStealer, a Windows malware that steals crypto assets, passwords and browser data while targeting more than 50 cryptocurrency wallets. According to security firm Morphisec, RevStealer previously circulated through GitHub repositories and gaming cheat-themed sites. In this campaign, the malware is disguised as a "Claude Opus 5 Free Desktop" project, impersonating AI developer Anthropic and promising free Claude access. The malware hunts for browser databases, cookies, password manager records, VPN and remote access settings, chat data, screenshots and specific documents. It also checks device memory, processor core count, hostname, username and graphics hardware, and monitors for debug delays typical of malware analysis environments. If it detects an anomaly, it stops the infection flow. If it passes checks, the payload is decrypted, stored under a random name and executed covertly. Separately, Russian security firm Kaspersky earlier found OkoBot, a malware framework aimed at crypto investors that can steal wallet files, browser data and user credentials. Cointelegraph reported the findings.

Fake Claude desktop apps are being used to distribute a Windows malware strain called RevStealer, which can steal crypto assets, passwords and browser data while targeting more than 50 cryptocurrency wallets.

Security firm Morphisec said RevStealer has previously spread through GitHub repositories and gaming cheat-themed websites. This time, it is disguised as a project named "Claude Opus 5 Free Desktop", posing as AI developer Anthropic and promising free access to Claude.

The malware searches for browser databases, cookies, password manager records, VPN and remote access settings, chat data, screenshots and specific documents. It also inspects device memory, processor core count, hostname, username and graphics hardware, while monitoring for debug delays that are common in malware analysis environments. If an anomaly is detected, the infection process stops. If everything looks normal, the payload is decrypted, stored under a random name and executed covertly.

Earlier, Russian security firm Kaspersky uncovered OkoBot, a malware framework aimed at crypto investors that can steal wallet files, browser data and user credentials.

The findings were reported by Cointelegraph.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
900

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.