← All news
CRYPTO NEWS

Fake Claude Desktop App Spreads Crypto-Stealing Malware

Cointelegraph · Adrian Zmudzinski

Cybersecurity firm Morphisec has uncovered a fake Claude desktop application distributing RevStealer malware designed to steal cryptocurrency, passwords, and browser data. The app impersonates Anthropic's project offering free access to Claude AI and spreads via GitHub repositories and cheat-related websites. RevStealer performs detailed system checks before executing its malicious payload and targets data from over 50 cryptocurrency wallets.

Malware Distribution via Fake Claude Application

According to Morphisec’s report, the latest spread of RevStealer malware is linked to a fake “Claude Opus 5 Free Desktop” app impersonating Anthropic’s development. This app lures users by promising free access to the popular AI Claude. Previously, RevStealer propagated through GitHub repositories and game cheat-related websites.

Capabilities and Features of RevStealer

RevStealer is a Windows malware designed to steal cryptocurrency, passwords, and browser information. It stealthily collects data from browser databases, cookies, password managers, VPN and remote access settings, messaging apps, screenshots, and select documents. Importantly, it targets more than 50 types of cryptocurrency wallets.

Detection Evasion and Device Validation Techniques

Before activating its malicious payload, RevStealer assesses the device environment, checking available RAM, number of processor cores, hostname, username, and graphics hardware. It also monitors for debugging delays typical in malware analysis environments. If it detects anomalies or signs of investigation, it aborts malicious activity. When the device passes these checks, the payload is decrypted, saved under a random filename, and executed covertly.

Concurrent Cybersecurity Findings Targeting Crypto Investors

Morphisec’s report follows shortly after Russian cybersecurity firm Kaspersky’s discovery of a new malware framework named OkoBot. Similar to RevStealer, OkoBot targets cryptocurrency investors, harvesting wallet files, browser data, user credentials, injecting malicious extensions, and capturing wallet application windows to steal assets.

Why it matters

This news is significant because it reveals evolving malware distribution methods targeting cryptocurrency investors through fake applications that exploit user trust in reputable AI projects. The meticulous device checks before payload activation demonstrate advancing anti-detection techniques that complicate antivirus efforts. Understanding these threats equips users and cybersecurity professionals to remain vigilant and respond promptly to such malicious activity.

Prepared from the source material with AI-assisted editing and checked against the supplied facts.

Open original source ↗