Fake AI App Distributes Stealthy Credential Theft Tool RevStealer
Threat actors are exploiting demand for generative AI tools to distribute RevStealer, a Windows-focused information stealer hidden inside a trojanized Electron application that impersonates a free desktop version of Anthropic's Claude Opus 5.
The campaign uses GitHub repositories and game-cheat-themed websites to entice victims into downloading what appears to be a legitimate AI application.
Instead, the executable is a stealthy credential theft tool engineered to evade sandboxes, endpoint monitoring, and post-infection investigation.
The malware targets browser databases, encryption keys, stored credentials, cookies, extension data, cryptocurrency wallets, password managers, VPN configurations, Windows Credential Manager entries, and remote-access artifacts.