All NewsEducationTVBrokers
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

Fake Claude desktop app distributes crypto-stealing malware

Created at 1 Sep · 2:06 PM1 source↑ Market-relevant
IN SHORT

A fake Claude desktop application is being used to distribute RevStealer, a Windows malware strain designed to steal cryptocurrency, passwords, and browser data. The malware impersonates AI developer Anthropic and promises free access to Claude Opus 5.

Key Numbers

50+cryptocurrency wallets targeted

Who's Involved

Morphisec
cybersecurity company that reported on RevStealer
Kaspersky
cybersecurity company that discovered OkoBot malware
Anthropic
AI developer impersonated by the fake Claude app

↳ Why This Matters

The proliferation of sophisticated malware disguised as legitimate AI tools poses a significant threat to cryptocurrency holders and general internet users, highlighting the need for increased cybersecurity vigilance and awareness of phishing tactics.

Key facts

  • A fake "Claude Opus 5 Free Desktop" application is distributing RevStealer malware.
  • RevStealer is designed to steal data from over 50 cryptocurrency wallets.
  • The malware also targets browser passwords, cookies, messaging data, and selected documents.
  • RevStealer employs checks to avoid detection in malware analysis environments.
  • The malware impersonates AI developer Anthropic to lure users.

A fake desktop application impersonating Anthropic's Claude AI is being used to distribute RevStealer, a malware strain capable of stealing cryptocurrency, browser passwords, and other sensitive data. Cybersecurity firm Morphisec reported that the malware, disguised as a free version of "Claude Opus 5," is designed to evade detection by checking for signs of analysis environments before deploying its malicious payload.

RevStealer targets over 50 cryptocurrency wallets, along with browser databases, password manager records, VPN settings, messaging data, screenshots, and selected documents. The malware is programmed to identify and avoid systems that appear to be set up for malware analysis, such as those with specific memory configurations or debugging delays.

This discovery follows similar threats, including OkoBot, a malware framework identified by Kaspersky that also targets cryptocurrency investors by harvesting wallet files and credentials. Microsoft has also previously warned users about 'Crypto Clipper' malware spread via USB drives.

Frequently asked questions

RevStealer is a Windows malware strain designed to steal cryptocurrency, browser passwords, messaging data, and selected documents. It is being distributed through a fake Claude desktop application.

The fake application, presented as a free version of 'Claude Opus 5', lures users into downloading and running the malware, which then checks the system for analysis environments before executing its malicious payload.

RevStealer targets over 50 cryptocurrency wallets, browser passwords, cookies, messaging data, VPN and remote-access settings, screenshots, and selected documents.

What Happens Next

01Users are advised to exercise caution with AI desktop applications.
02Security researchers will continue to monitor for new malware distribution tactics.

How It Developed

A fake Claude desktop application is distributing RevStealer malware.
RevStealer targets over 50 crypto wallets, browser passwords, messaging data, and documents.
The malware impersonates Anthropic's Claude Opus 5 and promises free access.
RevStealer checks for signs of analysis environments before deploying its payload.
Kaspersky previously discovered OkoBot malware targeting cryptocurrency investors.

Sources

T1
Fake Claude desktop app spreads crypto-stealing malwareRevStealer targets more than 50 crypto wallets alongside browser passwords, cookies, messaging data and selected documents.Cointelegraph

Related Stories

Anthropic tightens AI training security after models accessed unauthorized systems
1 Sep · 2:16 AM
OpenAI denies Apple trade secret theft allegations
31 Aug · 8:44 PM
AIR raises $50M for AI agent security and vetting platform
1 Sep · 4:11 PM
Anthropic signs $35 billion cloud deal with Nvidia-backed Lambda
1 Sep · 12:53 AM
Hackers claim millions of patient records stolen from McKesson
31 Aug · 6:21 PM