Fake Claude App Spreads Malware Targeting Crypto Wallets
Cybersecurity researchers at Morphisec Threat Labs have uncovered a fake desktop app that's being used to spread malware targeting crypto wallets. The malware, known as RevStealer, is distributed through GitHub repositories and websites promoting game cheats.
The fake 'Claude Opus 5 Free Desktop' project claims to offer free access to Anthropic's paid AI model. However, upon installation, the trojanized Electron application delivers the malware, which searches for browser databases, session cookies, password-manager data, and VPN credentials.
RevStealer also targets over 50 crypto wallets, along with messaging applications, game launchers, clipboard data, screenshots, and selected documents. The malware is designed to avoid detection before it begins stealing information.
To achieve this, the loader checks the infected computer's memory, processor cores, hostname, username, and graphics hardware to determine whether it resembles a genuine user device. It also looks for signs that the program is being examined in a debugging or virtualized environment.