BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Counterfeit Claude Desktop App Spreads RevStealer, Targeting Over 50 Crypto Wallets

2026-09-01 14:10

Odaily News: A counterfeit Claude desktop app is being used to spread the Windows malware RevStealer, which can steal crypto assets, passwords, and browser data while targeting more than 50 crypto wallets.

Cybersecurity firm Morphisec stated that RevStealer has previously been distributed via GitHub repositories and gaming cheat-themed websites; this time, it is also disguised as a "Claude Opus 5 Free Desktop" project, impersonating AI developer Anthropic and promising free access to Claude.

The malware searches browser databases, cookies, password manager records, VPN and remote access settings, chat data, screenshots, and specific documents, while also checking device memory, processor core count, hostname, username, and graphics hardware.

RevStealer monitors for debugging delays commonly found in malware analysis environments. If anomalies are detected, the malware will not proceed with the infection process; once checks are passed, its payload is decrypted, stored under a random name, and executed covertly. Previously, Russian cybersecurity firm Kaspersky discovered a malware framework called OkoBot targeting crypto investors, capable of stealing wallet files, browser data, and user credentials. (Cointelegraph)