A fake Claude desktop application is being used to distribute RevStealer, a Windows malware strain designed to steal crypto, password and browser data. According to Cointelegraph, cybersecurity company Morphisec said in a Monday report that RevStealer was previously spread through GitHub repositories and game-cheat-themed sites, but the most notable campaign involved a fake “Claude Opus 5 Free Desktop” project that impersonates AI developer Anthropic and promises free access to Claude. The researchers said the malware is built to leave few traces and searches browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots and selected documents. It also targets over 50 cryptocurrency wallets, making it a broad threat to users who store digital assets on affected devices.
Morphisec said RevStealer first checks whether a machine appears to be a real user device before unlocking its malicious payload. The malware examines available memory, the number of processor cores, hostname, username and graphics hardware, while also monitoring for the debugging delays commonly associated with malware analysis environments. If it detects anything unusual, it does not proceed to later stages of infection or malicious activity. If the system passes those checks, the payload is decrypted, saved under a random name and executed covertly. The report said this behavior is intended to help the malware avoid detection and reduce the chances that security tools or analysts can identify it before it begins stealing data from the compromised system.
The report comes after Russian cybersecurity company Kaspersky disclosed a separate malware framework targeting cryptocurrency investors called OkoBot. Kaspersky said OkoBot can harvest crypto wallet files, browser data and user credentials, inject malicious extensions and capture wallet application windows to steal assets. The findings highlight continued malware activity aimed at crypto users, with attackers using different delivery methods and infection techniques to collect sensitive information from browsers, wallets and related applications. Both reports point to ongoing efforts by threat actors to disguise malicious software as legitimate tools or services in order to reach users who may be looking for software downloads tied to crypto or AI-related products.