Regulation

Fake Claude Desktop App Deploys RevStealer Malware Targeting Over 50 Crypto Wallets

Morphisec found RevStealer being distributed through a project promising a free desktop version of Claude, which Anthropic does not offer. The malware searches for more than 50 wallets, saved passwords and session cookies.

⏱ 2 min read Regulation
Quick Summary
  • A fake 'Claude Opus 5 Free Desktop' app is delivering RevStealer, a Windows malware that targets over 50 cryptocurrency wallets plus browser, VPN, and messaging data
  • RevStealer uses system checks on memory, CPU cores, hostname, and GPU to detect analysis environments and halts infection if anything appears suspicious
  • Kaspersky separately identified OkoBot, another malware framework designed to harvest crypto wallet files and inject malicious browser extensions

A fraudulent desktop application impersonating Anthropic’s Claude AI has been identified as a delivery vehicle for RevStealer, a Windows-based information-stealing malware capable of draining cryptocurrency wallets and harvesting sensitive browser and messaging data, according to a report published Monday by cybersecurity firm Morphisec.

How the Attack Works

The most notable distribution vector is a fake project called ‘Claude Opus 5 Free Desktop,’ which mimics AI developer Anthropic and promises users free access to Claude. Morphisec researchers noted that RevStealer had also previously circulated through GitHub repositories and game-cheat-themed websites before this more sophisticated impersonation campaign emerged.

The lure is worth pausing on, because it is the part a reader can actually check. There is no free desktop edition of Claude to download. An application offering one is offering something that does not exist, which is the oldest signal in this kind of attack and the one that generalises to every future version of it.

Once deployed, the malware conducts an extensive sweep of infected Windows machines, targeting browser databases, cookies, password-manager records, VPN and remote-access configuration files, messaging application data, screenshots, and selected documents. Critically, RevStealer is built to attack more than 50 cryptocurrency wallets.

The cookies matter as much as the passwords. A stolen session cookie is already past two-factor authentication, so an account can be taken over without the attacker ever needing a code.

Anti-Detection Evasion Built In

RevStealer is engineered to avoid triggering security analysis tools. Before releasing its malicious payload, the malware runs a series of system checks, examining available memory, processor core count, hostname, username, and installed graphics hardware. It also monitors for debugging delays that are characteristic of controlled malware analysis environments.

If any of these checks return suspicious results, the malware halts and does not proceed to infection or data exfiltration. Only when all checks pass does the payload decrypt itself, adopt a randomly generated filename, and execute covertly on the machine.

Part of a Wider Wave of AI-Lure Malware

The Morphisec findings arrive alongside a separate discovery by Russian cybersecurity company Kaspersky, which identified a distinct malware framework called OkoBot. According to Kaspersky, OkoBot targets cryptocurrency investors and is capable of harvesting crypto wallet files, browser data, and user credentials, injecting malicious browser extensions, and capturing wallet application windows to steal digital assets.

Crypto users on Windows are advised to download AI applications exclusively from official developer websites and to verify software authenticity before installation.

⚖️ Our Verdict ⚖️ Watch and Wait

There is no market call in a malware campaign, but there is something worth taking away. The bait was a free desktop version of a product that does not have one, and that is checkable in seconds by anyone before they download anything. The detail most people miss is the cookie theft, because a stolen session cookie is already past two-factor authentication and gets an account taken over without a password or a code.