Fake Claude App Spreads RevStealer Malware to Over 50 Crypto Wallets
A new malware campaign is targeting cryptocurrency users by distributing a fake 'Claude Opus 5 Free Desktop' application, which conceals RevStealer, a data-stealing malware.
According to Morphisec's research, the malware has been distributed through various channels, including GitHub repositories and websites advertising video game cheats. The download arrives as an archive of approximately 101 megabytes containing a 64-bit Electron application that claims to offer free access to Anthropic's paid artificial intelligence model.
The program opens no visible window but instead prepares an encrypted native payload in the background, which is stored as an AES-256-CBC-encrypted resource inside the application. The loader attempts to add the user's AppData folder to the Microsoft Defender exclusion list to limit the evidence left on the device.
RevStealer checks for signs that security researchers are watching and requires at least 2 gigabytes of physical memory, two logical processor cores, and a recognized graphics adapter. It also conducts several other checks to determine if it is running on a virtual machine or analysis environment.