Fake Claude Desktop App Delivers Crypto-Stealing Malware
Cybersecurity firm Morphisec has reported that a fake desktop application impersonating Anthropic's Claude is being used to deliver RevStealer, a Windows malware family designed to steal sensitive information from victims and target cryptocurrency wallets. The campaign has evolved beyond earlier distribution methods, with the most prominent lure being a project called 'Claude Opus 5 Free Desktop', which suggests free access to Claude while disguising malware intended to steal crypto and broader account credentials.
RevStealer focuses on stealth, searching browser data, cookies, password-manager records, VPN/remote-access settings, and selected files. It targets over 50 cryptocurrency wallets and attempts to avoid analysis by checking for 'real user' environments. The malware also includes environment and debugging-delay checks, halting further activity if the system doesn't meet the criteria.
Morphisec notes that RevStealer was previously pushed through channels such as GitHub repositories and websites themed around game cheating. However, the firm highlights a more noticeable ruse: a counterfeit 'Claude Opus 5 Free Desktop' project that mimics the branding of AI developer Anthropic and presents the promise of free Claude access.
This trend reflects how crypto-targeting threats increasingly blend into everyday software expectations. Instead of asking victims to install a clearly suspicious file, attackers wrap their payloads in familiar UI assumptions, an 'app' users might treat as legitimate productivity software.