Malicious Claude Clone Spreads Crypto Wallet-Stealing Malware
Crypto users are being targeted by a malicious campaign that leverages a counterfeit desktop client mimicking Anthropic's Claude AI assistant to deploy RevStealer information-stealing malware.
The fraudulent application, dubbed 'Claude Opus 5 Free Desktop,' is distributed through GitHub repositories and exploits Anthropic's brand identity to deceive victims into downloading it under the pretense of accessing premium AI capabilities without charge.
Once installed, the executable masquerades as legitimate software but operates covertly in the background while staging its malicious components. The malware conducts extensive system profiling to verify it isn't operating within a controlled research environment and employs sophisticated evasion tactics to bypass security research and analysis environments.
RevStealer initiates comprehensive data harvesting operations across browser profiles, stored credentials, and cryptocurrency wallet storage, compromising more than 50 digital currency wallets and 12 password management applications. The stolen information is transmitted to remote infrastructure before the malware self-destructs, leaving no forensic evidence behind.