Fake Claude Desktop App Spreads RevStealer, Targeting Over 50 Crypto Wallets
Odaily News: Fake Claude desktop apps are being used to spread the Windows malware RevStealer, which can steal crypto assets, passwords, and browser data, and targets over 50 crypto wallets.
Cybersecurity firm Morphisec says RevStealer has previously been distributed via GitHub repositories and gaming cheat-themed websites; this time it is also disguised as a "Claude Opus 5 Free Desktop" project, impersonating AI developer Anthropic and promising free access to Claude.
The malware searches browser databases, cookies, password manager records, VPN and remote access settings, chat data, screenshots, and specific documents, and checks device memory, processor core count, hostname, username, and graphics hardware.
RevStealer monitors for debugging delays common in malware analysis environments. If anomalies are detected, the malware does not continue the infection process; after passing checks, its payload is decrypted, stored under a random name, and executed covertly. Previously, Russian cybersecurity firm Kaspersky discovered the malware framework OkoBot targeting crypto investors, which can steal wallet files, browser data, and user credentials. (Cointelegraph)
This content is for informational and educational purposes only and does not constitute investment advice related to BTCC. BTCC makes every effort but cannot guarantee the truthfulness, accuracy, or originality of the content above.