A fraudulent desktop application impersonating Anthropic’s Claude AI has been identified as a delivery vehicle for RevStealer, a Windows-based information-stealing malware capable of draining cryptocurrency wallets and harvesting sensitive browser and messaging data, according to a report published Monday by cybersecurity firm Morphisec.
How the Attack Works
The most notable distribution vector is a fake project called ‘Claude Opus 5 Free Desktop,’ which mimics AI developer Anthropic and promises users free access to Claude. Morphisec researchers noted that RevStealer had also previously circulated through GitHub repositories and game-cheat-themed websites before this more sophisticated impersonation campaign emerged.
The lure is worth pausing on, because it is the part a reader can actually check. There is no free desktop edition of Claude to download. An application offering one is offering something that does not exist, which is the oldest signal in this kind of attack and the one that generalises to every future version of it.
Once deployed, the malware conducts an extensive sweep of infected Windows machines, targeting browser databases, cookies, password-manager records, VPN and remote-access configuration files, messaging application data, screenshots, and selected documents. Critically, RevStealer is built to attack more than 50 cryptocurrency wallets.
The cookies matter as much as the passwords. A stolen session cookie is already past two-factor authentication, so an account can be taken over without the attacker ever needing a code.
Anti-Detection Evasion Built In
RevStealer is engineered to avoid triggering security analysis tools. Before releasing its malicious payload, the malware runs a series of system checks, examining available memory, processor core count, hostname, username, and installed graphics hardware. It also monitors for debugging delays that are characteristic of controlled malware analysis environments.
If any of these checks return suspicious results, the malware halts and does not proceed to infection or data exfiltration. Only when all checks pass does the payload decrypt itself, adopt a randomly generated filename, and execute covertly on the machine.
Part of a Wider Wave of AI-Lure Malware
The Morphisec findings arrive alongside a separate discovery by Russian cybersecurity company Kaspersky, which identified a distinct malware framework called OkoBot. According to Kaspersky, OkoBot targets cryptocurrency investors and is capable of harvesting crypto wallet files, browser data, and user credentials, injecting malicious browser extensions, and capturing wallet application windows to steal digital assets.
Crypto users on Windows are advised to download AI applications exclusively from official developer websites and to verify software authenticity before installation.


