Skip to content
Back to Guavy Wire
Crypto

Fake Claude App Spreads Malware Targeting Crypto Wallets

Share

Cybersecurity researchers at Morphisec Threat Labs have uncovered a fake desktop app that's being used to spread malware targeting crypto wallets. The malware, known as RevStealer, is distributed through GitHub repositories and websites promoting game cheats.

The fake 'Claude Opus 5 Free Desktop' project claims to offer free access to Anthropic's paid AI model. However, upon installation, the trojanized Electron application delivers the malware, which searches for browser databases, session cookies, password-manager data, and VPN credentials.

RevStealer also targets over 50 crypto wallets, along with messaging applications, game launchers, clipboard data, screenshots, and selected documents. The malware is designed to avoid detection before it begins stealing information.

To achieve this, the loader checks the infected computer's memory, processor cores, hostname, username, and graphics hardware to determine whether it resembles a genuine user device. It also looks for signs that the program is being examined in a debugging or virtualized environment.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc