Fake Claude app targets 50+ crypto wallets with RevStealer

10 hours ago 1



A fake Claude desktop application has distributed RevStealer malware designed to steal data from more than 50 cryptocurrency wallets, password managers, and web browsers on Windows computers. Summary RevStealer is hidden inside a fake “Claude Opus 5 Free Desktop” application. The malware targets more than 50 crypto wallets and 12 password managers. System checks prevent the payload from running in some virtual machines and analysis environments. RevStealer sends stolen data in encrypted records before deleting itself from the device. Fake Claude app conceals RevStealer payload Cybersecurity company Morphisec said in an Aug. 31 report that RevStealer is being delivered through a trojanized Electron application presented as “Claude Opus 5 Free Desktop,” which uses Anthropic’s branding and offers free access to its paid artificial intelligence model. Before appearing under the Claude name, the malware was distributed through GitHub repositories and websites advertising video game cheats, according to Morphisec Threat Labs. The researchers identified the Claude-themed GitHub project as the most notable example because it used interest in paid AI tools to encourage people to install unv...

Read Entire Article