RevStealer Malware Spreads Through Fake Claude App
A new malware strain called RevStealer is spreading through a fake Claude desktop application. The app, which promises free access to AI developer Anthropic's Claude, is actually designed to steal crypto, password, and browser data.
The malware checks the system before unleashing its payload, looking for signs of debugging or analysis environment activity. If it detects anything unusual, RevStealer won't proceed with the infection. However, if the system passes these checks, the payload is decrypted and covertly executed.
The malware targets over 50 cryptocurrency wallets, alongside browser passwords, cookies, messaging data, and selected documents. It also searches browser databases, password-manager records, VPN settings, and remote-access settings.