Fake Claude App Spreads Malware Targeting Crypto Wallets
A fake desktop application impersonating Anthropic's Claude is being used to distribute RevStealer malware, which targets cryptocurrency-related data and sensitive information. The malicious app, labeled 'Claude Opus 5 Free Desktop', promises free access to Claude but actually steals high-value information from browsers, password managers, wallet software, and selected documents.
Researchers at Morphisec found that RevStealer can target over 50 cryptocurrency wallets and capture messaging data and other credentials beyond crypto holdings. The malware checks system characteristics consistent with real user environments before executing its payload, making it difficult to detect.
This is not the first time a fake Claude project has been used to deliver malicious payloads. A similar campaign was reported earlier using GitHub repositories and game-cheat themed websites. The researchers warn that users should watch for new impersonation campaigns and suspicious installers promising free access to popular AI tools.