Fake Claude desktop app spreads crypto-stealing malware

Fake Claude desktop app spreads crypto-stealing malware img1
Spread the love

Written by Adrian Zmudzinskistaff writerReviewed by Yohan Yunstaff editor

Written by Adrian Zmudzinskistaff writer

Reviewed by Yohan Yunstaff editor

Fake Claude desktop app spreads crypto-stealing malware

Latest NewsPublishedSep 1, 2026

RevStealer targets more than 50 crypto wallets alongside browser passwords, cookies, messaging data and selected documents.

malware

A fake Claude desktop application is reportedly being used to distribute RevStealer, a Windows malware strain built to steal crypto, password and browser data.

as reported by a Monday report by cybersecurity company Morphisec, RevStealer was previously distributed through GitHub repositories and game-cheat-themed sites but the most notable is a fake “Claude Opus 5 Free Desktop” project that impersonates AI developer Anthropic and promises free access to Claude.

The researchers pointed out that the malware is designed to leave few traces and searches browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots and selected documents. RevStealer also targets over 50 cryptocurrency wallets.

The malware checks whether the machine looks like a real user device before unlocking its malicious payload, looking at available memory, the number of processor cores, hostname, username and graphics hardware. It also monitors for the debugging delays typical of malware analysis environment.

If RevStealer detects anything out of the ordinary, it does not move on to the next stages of infection and malicious activity. If the system passes those checks, the payload is decrypted, stored under a random name and covertly executed.

The report follows the discovery by Russian cybersecurity company Kaspersky of a new malware framework targeting cryptocurrency investors called OkoBot, which can harvest crypto wallet files, browser data and user credentials, inject malicious extensions and capture wallet application windows to steal assets.

Related: Microsoft warns users of ‘Crypto Clipper’ malware spread via USB drives

1 minute letter

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

  • Malware
  • Scams & Cybercrime

More on the subject

More Markets lending reserve drained for $9.3M: Blockaid



Aug 31, 2026

Zoltan Vardai

Real Trump Coins denies launching GOLD token, blames ‘bad actors’



Aug 30, 2026

Helen Partz

Trump-promoted brand touts GOLD before token collapse



Aug 29, 2026

Helen Partz

More Markets lending reserve drained for $9.3M: Blockaid



Aug 31, 2026

Zoltan Vardai

Real Trump Coins denies launching GOLD token, blames ‘bad actors’



Aug 30, 2026

Helen Partz

Trump-promoted brand touts GOLD before token collapse



Aug 29, 2026

Helen Partz


💡 A Greener Way to Earn: Looking for a smarter, more sustainable way to earn and mining crypto? EcoPool Network is a cloud-based mining pool that does the heavy lifting on remote servers — so you earn rewards around the clock without worrying about overheating hardware or sky-high electricity bills. It’s lightweight, battery-friendly, and built for everyday users. Download EcoPool now and start mining & earning smarter today.

Spread the love

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these