Fake Claude Desktop App Used to Spread Malware Targeting Crypto Wallets

A fake desktop version of Anthropic's Claude AI is being used to distribute Windows malware designed to steal crypto wallets, passwords, and browser data, according to cybersecurity researchers.
Morphisec Threat Labs said in a Monday report that the malware, known as RevStealer, has been distributed through GitHub repositories and websites promoting game cheats. One of the campaigns uses a fake "Claude Opus 5 Free Desktop" project that claims to offer free access to Anthropic's paid AI model.
The malware is delivered through a trojanized Electron application that looks like legitimate software. Once installed, RevStealer can search for browser databases, session cookies, password-manager data, and VPN credentials. It also targets more than 50 crypto wallets, along with messaging applications, game launchers, clipboard data, screenshots, and selected documents.
More From Cryptoprowl:
RevStealer is built to avoid detection before it begins stealing information. Its loader checks the infected computer's memory, processor cores, hostname, username, and graphics hardware to determine whether it resembles a genuine user device. It also looks for signs that the program is being examined in a debugging or virtualized environment.
If those checks fail, the malware stops. When the system passes, the loader decrypts its payload, saves it under a randomly generated name, and runs it without displaying a visible window.
"The native payload resolves Windows APIs without an import table and calls the kernel through 14 indirect syscall wrappers, bypassing the exported functions where user-mode monitoring hooks sit," Morphisec said.
Furthermore, instead of storing stolen information in a single archive, it can send data in encrypted records to reduce the traces left.
The malware can also use a Polygon (CRYPTO: $MATIC) blockchain smart contract to obtain a backup command-and-control address if its primary server becomes unavailable. This allows its operators to change infrastructure without rebuilding the malware.

