Fake Claude desktop app spreads RevStealer malware targeting crypto wallets
A fake Windows desktop application named 'Claude Opus 5 Free Desktop' is distributing RevStealer malware to steal data from over 50 cryptocurrency wallets and browser sessions. Cybersecurity company Morphisec reports that the malware uses advanced evasion techniques, including system checks and Polygon blockchain backups. Meanwhile, Anthropic is warning users and revoking active sessions hijacked by infostealers to prevent unauthorized account usage.
Fake Claude desktop malware
▪Cybersecurity company Morphisec reported on August 31, 2026, that a fake Windows desktop application named 'Claude Opus 5 Free Desktop' is distributing RevStealer malware.
▪Before using the Claude branding, the RevStealer malware was distributed through GitHub repositories and websites advertising video game cheats, according to Morphisec Threat Labs.
▪The fake Claude application download arrives as a 101-megabyte archive containing a 64-bit Electron application that runs in the background without opening a visible window.
▪The fake 'Claude Opus 5 Free Desktop' application uses Anthropic's branding and promises free access to its paid artificial intelligence model to lure users into installing unverified software.
RevStealer evasion techniques
▪RevStealer performs system checks requiring at least 2 gigabytes of physical memory, two logical processor cores, a recognized graphics adapter, and a CAPTCHA interaction before executing its payload.
▪RevStealer avoids standard import tables and uses 14 indirect system-call wrappers to reach the Windows kernel while bypassing security monitoring functions.
▪The RevStealer loader stores its payload as an AES-256-CBC-encrypted resource, decrypts it into the Windows AppData directory, and attempts to add the folder to the Microsoft Defender exclusion list.
▪RevStealer terminates execution if it detects hostnames, usernames, or debugging delays associated with malware analysis environments, or if the system language is set to Russian, Ukrainian, or certain Central Asian languages.
▪RevStealer can recover alternative command-and-control server addresses from a smart contract on the Polygon blockchain if its primary server becomes unavailable.
Cryptocurrency wallet theft
▪Other malware campaigns, such as OkoBot, Lumma Stealer, and BlueNoroff operations, have similarly targeted cryptocurrency wallets using fake updates, recovery screens, or pirated downloads.
▪RevStealer is designed to target and extract data from more than 50 cryptocurrency wallets, password managers, and web browsers on Windows computers.
▪RevStealer does not establish persistence on infected computers, instead executing a single short burst of theft before deleting itself from the device.
Browser credential harvesting
▪Stolen browser session cookies allow attackers to bypass multi-factor authentication and reuse active login sessions without needing the victim's password.
▪Anthropic responded to the session compromises by revoking active Claude sessions, signing affected users out, deleting saved payment methods, and offering refunds for unauthorized charges.
▪Anthropic began contacting Claude users whose active login sessions were stolen by infostealer malware, which attackers used to access accounts and consume usage limits.
▪Anthropic identified several Windows-based infostealers, including Vidar, LummaC2, StealC, RedLine, and Acreed, as well as the macOS-based Atomic Stealer, in its investigation of compromised accounts.
Infostealer infection prevention
▪Anthropic advised affected users to remove malware from their computers, change credentials, revoke active sessions, and avoid downloading software from unofficial sources.
▪Anthropic warned users that signing out of Claude stops stolen sessions but does not remove the underlying malware from infected computers.
Story comments
Loading comments…