Skip to main content

Fake “Claude” Desktop App Distributes Crypto-Stealing Malware



A fake desktop application impersonating Anthropic’s Claude is reportedly being used as a delivery mechanism for RevStealer, a Windows malware strain designed to steal crypto-related data and other sensitive information. Researchers at Morphisec say the campaign has evolved beyond earlier distribution channels, including GitHub repositories and game-cheat themed sites, and that the “Claude Opus 5 Free Desktop” lure is now among the most prominent.



While the technical details are aimed at defenders, the operational choices behind RevStealer carry direct implications for users and anyone investing in or managing digital assets: the malware is built to avoid analysis, profile the infected machine, and then extract high-value information across browsers, password managers, wallet software, and even selected documents.



Key takeaways



  • RevStealer is delivered via a fake “Claude Opus 5 Free Desktop” Windows app that impersonates Anthropic and offers supposed free access.

  • The malware is designed to leave minimal traces and harvest browser data, cookies, password-manager records, VPN/remote-access settings, screenshots, and selected files.

  • It targets more than 50 cryptocurrency wallets and can also capture messaging data and other credentials beyond crypto holdings.

  • Before executing, it checks system characteristics consistent with real user environments and aborts if it detects signs of analysis or abnormal conditions.

  • Curious about broader context: Morphisec’s report follows Kaspersky’s earlier identification of OkoBot, a separate framework aimed at crypto investors.



A Claude-themed lure masks a crypto-stealing payload


In a Monday report, cybersecurity firm Morphisec described how RevStealer has been distributed through multiple fronts, with earlier campaigns using GitHub repositories and game-cheat themed websites. The latest and most notable delivery method, the researchers said, is a project branded as “Claude Opus 5 Free Desktop” that impersonates Anthropic and promises free access to Claude.



From an attacker’s perspective, this approach is logical: it repackages a familiar consumer brand into a Windows installer or desktop program, lowering user skepticism and increasing the odds that victims will run the malicious payload.



Designed to extract high-value data from browsers, wallets, and more


Morphisec’s analysis portrays RevStealer as a multi-purpose stealer. The malware not only searches browser databases and cookies, but also looks for password-manager records and configurations tied to privacy and remote access. In addition, it targets VPN and remote-access settings and collects messaging data, which can reveal account recovery paths, authentication workflows, or direct access tokens.



For crypto users, the most significant operational detail is wallet targeting. Morphisec said RevStealer targets over 50 cryptocurrency wallets, positioning the malware to compromise both the user’s general credentials and the specific applications most likely to contain or facilitate asset management.



The report also notes that the malware can capture screenshots and selected documents. That matters because some users store seed phrases, backup codes, or operational instructions in non-wallet files—making document harvesting an extra layer of financial opportunity for attackers.



Execution gating: it tries to spot “analysis” before it acts


One of the more defensive-relevant elements of RevStealer, according to Morphisec, is the way it determines whether a machine resembles a real user environment. The malware checks available memory, the number of CPU cores, hostname and username information, and graphics hardware characteristics. It also monitors for debugging delays that are typical in malware analysis setups.



If the checks fail—if the system presents signals that look automated, instrumented, or otherwise atypical—RevStealer does not progress to the next stages of infection and malicious activity.



When the system passes, the malware decrypts its payload, stores it under a randomly generated name, and executes it covertly. This workflow is designed to reduce the chance that researchers can quickly identify the complete payload chain and to make behavioral detection harder when the malicious component only activates under specific conditions.



RevStealer follows a wider pattern of crypto-investor targeting


The Morphisec report arrives after earlier reporting by Kaspersky on a new malware framework targeting cryptocurrency investors called OkoBot. Kaspersky’s description, as referenced in Morphisec’s write-up, indicates that OkoBot can harvest crypto wallet files and browser data, steal user credentials, inject malicious extensions, and capture wallet application windows to help redirect or siphon assets.



Taken together, the two stories suggest a persistent trend: attackers are not limiting themselves to “wallet-only” theft. Instead, they are expanding into browser and credential ecosystems, then coupling that access with wallet application targeting and, in RevStealer’s case, extensive environmental checks to avoid discovery.



For investors, traders, and operators of digital asset infrastructure, this matters because compromises rarely begin in the wallet UI itself. The intrusion surface is often broader: downloadable “desktop” apps, browser states, stored credentials, and remote-access configurations that attackers can convert into the ability to act on funds.



What to watch next


With fake Claude desktop projects being used to deliver a stealer that targets both wallets and sensitive browsing credentials, users should watch for new impersonation campaigns and suspicious installers that promise free access to popular AI tools. On the defensive side, prioritizing endpoint protection, restricting execution of unknown binaries, and maintaining clean browser and password-manager hygiene may help reduce the odds that malware like RevStealer finds a usable environment before it can activate.



https://www.cryptobreaking.com/fake-claude-desktop-app-distributes/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Fake%20“Claude”%20Desktop%20App%20Distributes%20Crypto-Stealing%20Malware%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

XRP vs. SOL: Massive Market Interest Gap Revealed by Exec

Here's the revised article with an introduction, key takeaways, and optimized for readability, SEO, and journalistic integrity while preserving the original HTML structure: --- As the crypto market continues to evolve, investor preferences remain primarily anchored around Bitcoin and Ethereum, with questions surrounding the next wave of promising digital assets. Recent insights from Coinbase Asset Management highlight the current sentiment and potential candidates vying for a top position in the rapidly expanding blockchain ecosystem. From institutional interest to network development, the race is on to identify the next asset that could join the ranks of dominant cryptocurrencies like Bitcoin and Ethereum. Investors predominantly view Bitcoin and Ethereum as the primary crypto assets for portfolio inclusion. Solana is seen as a tentative third choice, with XRP potentially vying for the next spot pending network growth. Ripple’s XRP is making strides, but market con...