Skip to main content

Fake Claude Desktop App Used to Deliver Crypto-Stealing Malware



A fake desktop application impersonating Anthropic’s Claude is reportedly being used as a delivery mechanism for RevStealer, a Windows malware family designed to harvest sensitive information from victims and then target a wide range of cryptocurrency wallets.


In a report published Monday, cybersecurity firm Morphisec says the campaign has evolved beyond earlier distribution methods that relied on GitHub repositories and game-cheat-themed sites, with one of the most prominent lures being a project dubbed “Claude Opus 5 Free Desktop.” The name suggests free access to Claude while disguising malware intended to steal crypto and broader account credentials.



Key takeaways



  • Morophisec links the latest RevStealer infections to a fake “Claude Opus 5 Free Desktop” download that impersonates Anthropic/Claude.

  • The malware focuses on stealth, including searches of browser data, cookies, password-manager records, VPN/remote-access settings, and selected files.

  • RevStealer targets more than 50 cryptocurrency wallets and attempts to avoid analysis by checking for “real user” environments.

  • Its staging includes environment and debugging-delay checks; if the system doesn’t meet the criteria, the malware halts further activity.



Fake Claude desktop lure points to continued social-engineering


According to Morphisec, RevStealer was previously pushed through channels such as GitHub repositories and websites themed around game cheating. While those delivery routes remain common for commodity malware, the firm highlights a more noticeable ruse: a counterfeit “Claude Opus 5 Free Desktop” project that mimics the branding of the AI developer Anthropic and presents the promise of free Claude access.


This matters for users because it reflects how crypto-targeting threats increasingly blend into everyday software expectations. Instead of asking victims to install a clearly suspicious file, attackers wrap their payloads in familiar UI assumptions—an “app” users might treat as legitimate productivity software.



What RevStealer looks for—and where it steals


Morphisec says RevStealer is built to minimize its forensic footprint while broadening the scope of harvested data. The malware searches browser databases and related artifacts such as cookies, password-manager records, and other stored session information.


The threat also goes beyond typical credential theft by collecting details connected to remote access and privacy tooling, including VPN and remote-access settings. It further targets messaging-related data and takes screenshots, alongside selected documents.


On the crypto side, Morphisec notes that RevStealer targets over 50 cryptocurrency wallets. For investors and everyday users, the key risk is that stolen wallet access can enable asset movement without needing the attacker to break the wallet software itself—if the victim’s wallet files or credentials are extracted, the next step can be direct unauthorized control.



Environment checks designed to frustrate researchers


A notable feature of the RevStealer infection chain, according to the Morphisec report, is a multi-part gating mechanism. Before unlocking the next stages, the malware checks whether the machine resembles a genuine user device.


The researchers describe checks based on available memory, processor core count, hostname and username characteristics, and graphics hardware. Morphisec also adds that RevStealer monitors for debugging delays that are typical in malware analysis environments.


If the malware detects anything it considers abnormal, it does not proceed further—meaning it can reduce the amount of observable behavior available to analysts and slow down detection efforts. When the checks pass, Morphisec reports that the payload is decrypted, saved under a random filename, and executed covertly.


For defenders, this implies that “it didn’t run” can be a deliberate outcome rather than a sign of a clean system. It also highlights why behavioral detection and endpoint monitoring still matter: relying solely on static indicators or single-run samples may miss threats that deliberately stall during investigation.



Broader trend: crypto-investor malware frameworks keep expanding


The RevStealer report lands amid other research targeting people involved with cryptocurrency investing. Earlier coverage referenced discovery by Kaspersky of a new malware framework called OkoBot, described as targeting crypto investors by harvesting wallet files, browser data, and user credentials.


As noted by Kaspersky in that separate discovery, OkoBot can also inject malicious extensions and capture wallet application windows to help steal assets. While the Morphisec write-up focuses specifically on RevStealer, both cases point to a persistent pattern: attackers are combining browser/session theft with wallet-targeted collection and increasingly using realistic lures.


For readers, the important takeaway is not just that malware exists, but that campaigns are diversifying their tooling and delivery methods while remaining aligned around a shared objective—access to crypto storage and the credentials needed to move money.



What users and teams should watch next


With scams now leveraging credible-sounding AI branding and malware that attempts to detect analysis environments, the immediate priority is operational hygiene: treat “free” desktop downloads—especially ones impersonating well-known companies—as high-risk, avoid installing unknown software from community-hosted pages, and verify integrity before execution. Meanwhile, security teams should expect more wallet-focused stealers that pair broad browser-data harvesting with stealthy, environment-aware execution.



https://www.cryptobreaking.com/fake-claude-desktop-app-used/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Fake%20Claude%20Desktop%20App%20Used%20to%20Deliver%20Crypto-Stealing%20Malware%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

XRP vs. SOL: Massive Market Interest Gap Revealed by Exec

Here's the revised article with an introduction, key takeaways, and optimized for readability, SEO, and journalistic integrity while preserving the original HTML structure: --- As the crypto market continues to evolve, investor preferences remain primarily anchored around Bitcoin and Ethereum, with questions surrounding the next wave of promising digital assets. Recent insights from Coinbase Asset Management highlight the current sentiment and potential candidates vying for a top position in the rapidly expanding blockchain ecosystem. From institutional interest to network development, the race is on to identify the next asset that could join the ranks of dominant cryptocurrencies like Bitcoin and Ethereum. Investors predominantly view Bitcoin and Ethereum as the primary crypto assets for portfolio inclusion. Solana is seen as a tentative third choice, with XRP potentially vying for the next spot pending network growth. Ripple’s XRP is making strides, but market con...