Crypto news report · source clearly identified

Fake Claude Desktop App Distributes RevStealer Crypto-Stealing Malware

RevStealer targets more than 50 crypto wallets alongside browser passwords, cookies, messaging data and selected documents.

A counterfeit "Claude Opus 5 Free Desktop" application is being used to spread RevStealer, a Windows‑based malware strain that harvests cryptocurrency wallet files, browser credentials, messaging data and other personal files.

Distribution channels

Security firm Morphisec reports that RevStealer has previously appeared on GitHub repositories and sites offering game cheats. The most prominent recent vector is a fake project that pretends to provide free access to Anthropic’s Claude AI.

Malware capabilities

RevStealer is designed to leave minimal traces while scanning browser databases, cookies, password‑manager records, VPN and remote‑access settings, messaging applications, screenshots and selected documents. It specifically targets over 50 cryptocurrency wallets.

Evasion techniques

Before activating its payload, the malware checks system characteristics such as memory size, CPU core count, hostname, username and graphics hardware to verify that it is running on a genuine user device. It also looks for debugging delays typical of analysis environments. If anomalies are detected, the infection halts; otherwise, the payload is decrypted, saved under a random name and executed covertly.

Related threats

The findings follow a report by Kaspersky on OkoBot, another malware framework aimed at crypto investors that can harvest wallet files, inject malicious browser extensions and capture wallet application windows.

Source & attribution

News Source

Publisher
Cointelegraph
Original date
September 1, 2026, 2:00 PM
Original headline
Fake Claude desktop app spreads crypto-stealing malware
View original report ↗