2026-09-01 CoinTelegraph

Fake Claude Desktop App Spreads RevStealer Crypto-Stealing Malware

Cybersecurity researchers at Morphisec have identified a malicious campaign distributing a Windows malware strain called RevStealer through a fake Anthropic-branded desktop application. The fraudulent project, titled "Claude Opus 5 Free Desktop," was promoted on GitHub and game-cheat-themed sites and lured victims with promises of free access to Anthropic's Claude AI assistant. Once installed, RevStealer harvests cryptocurrency wallet files, browser passwords, cookies, VPN and remote-access credentials, messaging data, screenshots, and selected documents.

RevStealer employs anti-analysis techniques to evade detection by sandboxed environments. Before deploying its malicious payload, the malware inspects system memory, processor core count, hostname, username, and graphics hardware, while monitoring for the debugging delays typical of malware analysis tools. If the device appears suspicious, infection is aborted. Systems that pass these checks have their payloads decrypted, stored under randomized filenames, and covertly executed with minimal forensic traces. The malware targets more than 50 cryptocurrency wallets, putting both retail and institutional holders at risk.

The disclosure follows Kaspersky's recent identification of OkoBot, a separate malware framework aimed at crypto investors through browser data harvesting, malicious browser extension injection, and wallet window capture. Microsoft has also warned of "Crypto Clipper" malware distributed via USB drives. Together, these campaigns underscore a growing trend of threat actors leveraging trusted AI and developer branding to distribute financially motivated malware, making source verification and endpoint monitoring critical for crypto users.

Read Full Article at CoinTelegraph →

Related Tool

Find Your ID

Try Now →
Check My ID