NewsLayer.com
NewsLayer PulseLIVEBTC$77,420-1.86%ETH$2,428-1.88%SOL$100.88-2.67%XRP$1.37-1.37%DOGE$0.0823-1.29%ADA$0.1978+0.01%Total Cap$2.74T-1.41%Layer Index49 Neutral

Fake Claude desktop app spreads crypto-stealing malware

RevStealer targets more than 50 crypto wallets alongside browser passwords, cookies, messaging data and selected documents.

Cointelegraph by Adrian Zmudzinski

Publisher Cointelegraph

Sep 1, 2026 at 2:00 PM UTC · 1 Min. Lesezeit

Fake Claude desktop app spreads crypto-stealing malware
Image via Cointelegraph
Übersetzung…

A fake Claude desktop application is reportedly being used to distribute RevStealer, a Windows malware strain built to steal crypto, password and browser data.

According to a Monday report by cybersecurity company Morphisec, RevStealer was previously distributed through GitHub repositories and game-cheat-themed sites but the most notable is a fake “Claude Opus 5 Free Desktop” project that impersonates AI developer Anthropic and promises free access to Claude.

The researchers noted that the malware is designed to leave few traces and searches browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots and selected documents. RevStealer also targets over 50 cryptocurrency wallets.

The malware checks whether the machine looks like a real user device before unlocking its malicious payload, looking at available memory, the number of processor cores, hostname, username and graphics hardware. It also monitors for the debugging delays typical of malware analysis environment.

If RevStealer detects anything out of the ordinary, it does not move on to the next stages of infection and malicious activity. If the system passes those checks, the payload is decrypted, stored under a random name and covertly executed.