Crypto news report · source clearly identified

Fake Claude App Distributes RevStealer Malware Targeting Over 50 Crypto Wallets

A counterfeit Claude desktop application has been used to deliver RevStealer, a Windows‑based malware that harvests credentials from more than 50 cryptocurrency wallets, password managers and browsers before self‑deleting.

A malicious version of the Claude AI desktop client has been identified as a delivery vector for RevStealer, a credential‑stealing malware that focuses on cryptocurrency assets. Security firm Morphisec detailed the infection chain, the anti‑analysis techniques employed, and the range of data exfiltrated.

Malware delivery and disguise

The payload is hidden inside a trojanized Electron application named “Claude Opus 5 Free Desktop.” The 101 MB archive pretends to provide free access to Anthropic’s paid AI model, using the Claude brand to lure users into installing unverified software.

Anti‑analysis safeguards

Before decrypting its payload, RevStealer performs a series of checks to avoid sandbox and research environments. These include:

  • Minimum hardware requirements (≥2 GB RAM, two CPU cores, a recognized GPU)
  • Hostname and username blocklists
  • Timing tests around JavaScript debugger instructions
  • Language checks that abort on Russian, Ukrainian and several Central Asian locales
  • A CAPTCHA that requires user interaction

If any check fails, the loader does not reveal the malicious code, limiting exposure to analysts.

Payload execution

When the checks pass, the loader decrypts an AES‑256‑CBC‑encrypted resource, writes it to a random file in the Windows AppData folder, and launches it without a visible window. It also attempts to add the AppData directory to Microsoft Defender’s exclusion list to reduce detection.

Data collection targets

RevStealer scans the compromised system for a wide range of sensitive information, including:

  • Windows Credential Manager entries
  • Credentials from 12 known password managers
  • Keys, seed phrases and session data from more than 50 cryptocurrency wallets
  • Browser databases, cookies and extension storage
  • VPN configurations, remote‑access credentials, clipboard contents, messaging app data, selected documents, screenshots, game launchers and OBS streaming profiles

Collected items are encrypted, packaged into typed records, and sent to the attacker’s command‑and‑control server.

Command‑and‑control resilience

If the primary server becomes unavailable, RevStealer can retrieve an alternative address from a smart contract on the Polygon blockchain, allowing operators to shift infrastructure without redeploying the malware.

No persistence, rapid exfiltration

The malware does not create scheduled tasks or startup entries. After gathering and transmitting data, it deletes itself, making detection a race against a “single short burst of theft.”

Context within broader crypto‑malware trends

Impersonating popular software to distribute credential‑stealing tools is a recurring tactic. Recent campaigns have used fake movie releases, counterfeit meeting invites and bogus recovery screens to harvest wallet data, passwords and private keys from victims worldwide.

Source & attribution

News Source

Publisher
crypto.news
Original date
September 1, 2026, 7:12 PM
Original headline
Fake Claude app targets 50+ crypto wallets with RevStealer
View original report ↗