Key facts
- A fake "Claude Opus 5 Free Desktop" application is distributing RevStealer malware.
- RevStealer is designed to steal data from over 50 cryptocurrency wallets.
- The malware also targets browser passwords, cookies, messaging data, and selected documents.
- RevStealer employs checks to avoid detection in malware analysis environments.
- The malware impersonates AI developer Anthropic to lure users.
A fake desktop application impersonating Anthropic's Claude AI is being used to distribute RevStealer, a malware strain capable of stealing cryptocurrency, browser passwords, and other sensitive data. Cybersecurity firm Morphisec reported that the malware, disguised as a free version of "Claude Opus 5," is designed to evade detection by checking for signs of analysis environments before deploying its malicious payload.
RevStealer targets over 50 cryptocurrency wallets, along with browser databases, password manager records, VPN settings, messaging data, screenshots, and selected documents. The malware is programmed to identify and avoid systems that appear to be set up for malware analysis, such as those with specific memory configurations or debugging delays.