Fake AI App Stole Sensitive Info from Browsers and Wallets
Cybersecurity researchers have discovered a malicious campaign using a fake AI application to steal sensitive information. The malware, known as RevStealer, is disguised as an Electron desktop application that impersonates Anthropic's Claude AI service.
The attackers created a fake 'Claude Opus 5 Free Desktop' project on GitHub repositories and promoted it on game-cheat-themed websites, exploiting growing interest in AI tools by promising free access to a paid AI model. The application is a trojanized version of the legitimate Electron desktop app.
Once executed, RevStealer collects sensitive information from browsers, password managers, cryptocurrency wallets, VPN applications, and other software. It targets session cookies, Windows Credential Manager data, clipboard contents, screenshots, and selected documents.