RevStealer targets over 50 crypto wallets through fake Claude app

  • RevStealer is distributed through a fake Claude desktop application using Anthropic branding.
  • RevStealer targets over 50 cryptocurrency wallets and 12 password managers.
  • Morphisec said the malware deletes itself after sending encrypted stolen data.

RevStealer, a Windows information stealer, is being distributed through a trojanized Electron application called "Claude Opus 5 Free Desktop" that uses Anthropic branding and promises free access to a paid artificial intelligence model. Morphisec said the malware targets more than 50 cryptocurrency wallets, 12 password managers, Windows Credential Manager, browser session cookies, VPN and remote-access credentials, clipboard contents, messaging data, selected documents, screenshots, game launchers and OBS profiles. The loader uses encrypted resources, Microsoft Defender exclusion attempts, anti-virtual-machine checks and a CAPTCHA barrier to evade analysis. On systems that pass its checks, RevStealer sends encrypted records to its command-and-control server, can retrieve an alternative server address from a Polygon smart contract, and deletes itself without establishing persistence. Morphisec said the malware was previously distributed through GitHub repositories and websites advertising video game cheats.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.