RevStealer Malware Campaign Impersonates AI Application
Cybersecurity researchers have uncovered a Windows information-stealing malware campaign disguised as a legitimate AI application. The malware, known as RevStealer, is delivered through a trojanized Electron desktop application that impersonates Anthropic's Claude AI service.
The campaign uses a fake 'Claude Opus 5 Free Desktop' project hosted through GitHub repositories and promoted on game-cheat-themed websites. This lure attempts to exploit growing interest in AI tools by promising free access to a paid AI model.
Once executed, RevStealer can collect sensitive information from browsers, password managers, cryptocurrency wallets, VPN applications, and other software. It also targets session cookies, Windows Credential Manager data, clipboard contents, screenshots, and selected documents.