Crypto news report · source clearly identified
Fake Claude Desktop App Distributes RevStealer Crypto-Stealing Malware
RevStealer targets more than 50 crypto wallets alongside browser passwords, cookies, messaging data and selected documents.

A counterfeit "Claude Opus 5 Free Desktop" application is being used to spread RevStealer, a Windows‑based malware strain that harvests cryptocurrency wallet files, browser credentials, messaging data and other personal files.
Distribution channels
Security firm Morphisec reports that RevStealer has previously appeared on GitHub repositories and sites offering game cheats. The most prominent recent vector is a fake project that pretends to provide free access to Anthropic’s Claude AI.
Malware capabilities
RevStealer is designed to leave minimal traces while scanning browser databases, cookies, password‑manager records, VPN and remote‑access settings, messaging applications, screenshots and selected documents. It specifically targets over 50 cryptocurrency wallets.
Evasion techniques
Before activating its payload, the malware checks system characteristics such as memory size, CPU core count, hostname, username and graphics hardware to verify that it is running on a genuine user device. It also looks for debugging delays typical of analysis environments. If anomalies are detected, the infection halts; otherwise, the payload is decrypted, saved under a random name and executed covertly.
Related threats
The findings follow a report by Kaspersky on OkoBot, another malware framework aimed at crypto investors that can harvest wallet files, inject malicious browser extensions and capture wallet application windows.
Source & attribution
News Source
- Publisher
- Cointelegraph
- Original date
- September 1, 2026, 2:00 PM
- Original headline
- Fake Claude desktop app spreads crypto-stealing malware