Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Fake Claude desktop app spreads RevStealer malware targeting crypto wallets
00

Fake Claude desktop app spreads RevStealer malware targeting crypto wallets

Aug 31, 2026

A fake Windows desktop application named 'Claude Opus 5 Free Desktop' is distributing RevStealer malware to steal data from over 50 cryptocurrency wallets and browser sessions. Cybersecurity company Morphisec reports that the malware uses advanced evasion techniques, including system checks and Polygon blockchain backups. Meanwhile, Anthropic is warning users and revoking active sessions hijacked by infostealers to prevent unauthorized account usage.

Fake Claude desktop malware

  • ▪Cybersecurity company Morphisec reported on August 31, 2026, that a fake Windows desktop application named 'Claude Opus 5 Free Desktop' is distributing RevStealer malware.
  • ▪Before using the Claude branding, the RevStealer malware was distributed through GitHub repositories and websites advertising video game cheats, according to Morphisec Threat Labs.
  • ▪The fake Claude application download arrives as a 101-megabyte archive containing a 64-bit Electron application that runs in the background without opening a visible window.
  • ▪The fake 'Claude Opus 5 Free Desktop' application uses Anthropic's branding and promises free access to its paid artificial intelligence model to lure users into installing unverified software.

RevStealer evasion techniques

  • ▪RevStealer performs system checks requiring at least 2 gigabytes of physical memory, two logical processor cores, a recognized graphics adapter, and a CAPTCHA interaction before executing its payload.
  • ▪RevStealer avoids standard import tables and uses 14 indirect system-call wrappers to reach the Windows kernel while bypassing security monitoring functions.
  • ▪The RevStealer loader stores its payload as an AES-256-CBC-encrypted resource, decrypts it into the Windows AppData directory, and attempts to add the folder to the Microsoft Defender exclusion list.
  • ▪RevStealer terminates execution if it detects hostnames, usernames, or debugging delays associated with malware analysis environments, or if the system language is set to Russian, Ukrainian, or certain Central Asian languages.
  • ▪RevStealer can recover alternative command-and-control server addresses from a smart contract on the Polygon blockchain if its primary server becomes unavailable.

Cryptocurrency wallet theft

  • ▪Other malware campaigns, such as OkoBot, Lumma Stealer, and BlueNoroff operations, have similarly targeted cryptocurrency wallets using fake updates, recovery screens, or pirated downloads.
  • ▪RevStealer is designed to target and extract data from more than 50 cryptocurrency wallets, password managers, and web browsers on Windows computers.
  • ▪RevStealer does not establish persistence on infected computers, instead executing a single short burst of theft before deleting itself from the device.

Browser credential harvesting

  • ▪Stolen browser session cookies allow attackers to bypass multi-factor authentication and reuse active login sessions without needing the victim's password.
  • ▪RevStealer harvests browser databases, saved passwords, session cookies, VPN configurations, remote-access credentials, clipboard contents, and messaging application data.

Anthropic session compromise response

  • ▪Anthropic responded to the session compromises by revoking active Claude sessions, signing affected users out, deleting saved payment methods, and offering refunds for unauthorized charges.
  • ▪Anthropic began contacting Claude users whose active login sessions were stolen by infostealer malware, which attackers used to access accounts and consume usage limits.
  • ▪Anthropic identified several Windows-based infostealers, including Vidar, LummaC2, StealC, RedLine, and Acreed, as well as the macOS-based Atomic Stealer, in its investigation of compromised accounts.

Infostealer infection prevention

  • ▪Anthropic advised affected users to remove malware from their computers, change credentials, revoke active sessions, and avoid downloading software from unofficial sources.
  • ▪Anthropic warned users that signing out of Claude stops stolen sessions but does not remove the underlying malware from infected computers.

3 sources

Crypto
Fake Claude app targets 50+ crypto wallets with RevStealer
View source article
Cointelegraph
Fake Claude App Spreads RevStealer Crypto Malware
View source article
Firstpost
Anthropic warns Claude users after infostealers hijack active login sessions
View source article

Featured stories

View more in Crypto privacy & surveillance

OpenAI agents hijacked German website in previously undisclosed breakout incident

Sep 3, 2026 · 5 sources

Linux kernel vulnerabilities surge to nearly 2,000 per release as AI bug hunters overwhelm maintainers

Sep 1, 2026 · 1 source

Bank of England governor warns AI models threaten global financial stability

Aug 31, 2026 · 4 sources

Anthropic warns Claude users after infostealer malware hijacks active login sessions

Aug 30, 2026 · 4 sources

Story comments

Loading comments…

Related Projects

Anthropic

Topics

Crypto privacy & surveillanceAI security

Featured stories

View more in Crypto privacy & surveillance

OpenAI agents hijacked German website in previously undisclosed breakout incident

Sep 3, 2026 · 5 sources

Linux kernel vulnerabilities surge to nearly 2,000 per release as AI bug hunters overwhelm maintainers

Sep 1, 2026 · 1 source

Bank of England governor warns AI models threaten global financial stability

Aug 31, 2026 · 4 sources

Anthropic warns Claude users after infostealer malware hijacks active login sessions

Aug 30, 2026 · 4 sources