Fake“Claude” Desktop App Distributes Crypto-Stealing Malware
While the technical details are aimed at defenders, the operational choices behind RevStealer carry direct implications for users and anyone investing in or managing digital assets: the malware is built to avoid analysis, profile the infected machine, and then extract high-value information across browsers, password managers, wallet software, and even selected documents.
Key takeaways- RevStealer is delivered via a fake“Claude Opus 5 Free Desktop” Windows app that impersonates Anthropic and offers supposed free access. The malware is designed to leave minimal traces and harvest browser data, cookies, password-manager records, VPN/remote-access settings, screenshots, and selected files. It targets more than 50 cryptocurrency wallets and can also capture messaging data and other credentials beyond crypto holdings. Before executing, it checks system characteristics consistent with real user environments and aborts if it detects signs of analysis or abnormal conditions. Curious about broader context: Morphisec's report follows Kaspersky's earlier identification of OkoBot, a separate framework aimed at crypto investors.
In a Monday report, cybersecurity firm Morphisec described how RevStealer has been distributed through multiple fronts, with earlier campaigns using GitHub repositories and game-cheat themed websites. The latest and most notable delivery method, the researchers said, is a project branded as“Claude Opus 5 Free Desktop” that impersonates Anthropic and promises free access to Claude.
From an attacker's perspective, this approach is logical: it repackages a familiar consumer brand into a Windows installer or desktop program, lowering user skepticism and increasing the odds that victims will run the malicious payload.
Designed to extract high-value data from browsers, wallets, and moreMorphisec's analysis portrays RevStealer as a multi-purpose stealer. The malware not only searches browser databases and cookies, but also looks for password-manager records and configurations tied to privacy and remote access. In addition, it targets VPN and remote-access settings and collects messaging data, which can reveal account recovery paths, authentication workflows, or direct access tokens.
For crypto users, the most significant operational detail is wallet targeting. Morphisec said RevStealer targets over 50 cryptocurrency wallets, positioning the malware to compromise both the user's general credentials and the specific applications most likely to contain or facilitate asset management.
The report also notes that the malware can capture screenshots and selected documents. That matters because some users store seed phrases, backup codes, or operational instructions in non-wallet files-making document harvesting an extra layer of financial opportunity for attackers.
Execution gating: it tries to spot“analysis” before it actsOne of the more defensive-relevant elements of RevStealer, according to Morphisec, is the way it determines whether a machine resembles a real user environment. The malware checks available memory, the number of CPU cores, hostname and username information, and graphics hardware characteristics. It also monitors for debugging delays that are typical in malware analysis setups.
If the checks fail-if the system presents signals that look automated, instrumented, or otherwise atypical-RevStealer does not progress to the next stages of infection and malicious activity.
When the system passes, the malware decrypts its payload, stores it under a randomly generated name, and executes it covertly. This workflow is designed to reduce the chance that researchers can quickly identify the complete payload chain and to make behavioral detection harder when the malicious component only activates under specific conditions.
RevStealer follows a wider pattern of crypto-investor targetingThe Morphisec report arrives after earlier reporting by Kaspersky on a new malware framework targeting cryptocurrency investors called OkoBot. Kaspersky's description, as referenced in Morphisec's write-up, indicates that OkoBot can harvest crypto wallet files and browser data, steal user credentials, inject malicious extensions, and capture wallet application windows to help redirect or siphon assets.
Taken together, the two stories suggest a persistent trend: attackers are not limiting themselves to“wallet-only” theft. Instead, they are expanding into browser and credential ecosystems, then coupling that access with wallet application targeting and, in RevStealer's case, extensive environmental checks to avoid discovery.
For investors, traders, and operators of digital asset infrastructure, this matters because compromises rarely begin in the wallet UI itself. The intrusion surface is often broader: downloadable“desktop” apps, browser states, stored credentials, and remote-access configurations that attackers can convert into the ability to act on funds.
What to watch nextWith fake Claude desktop projects being used to deliver a stealer that targets both wallets and sensitive browsing credentials, users should watch for new impersonation campaigns and suspicious installers that promise free access to popular AI tools. On the defensive side, prioritizing endpoint protection, restricting execution of unknown binaries, and maintaining clean browser and password-manager hygiene may help reduce the odds that malware like RevStealer finds a usable environment before it can activate.
Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment