HomeCoinsLitecoinFake Claude App Spreads RevStealer Crypto Malware

Fake Claude App Spreads RevStealer Crypto Malware

A fake Claude desktop application is reportedly being used to distribute RevStealer, a Windows malware strain built to steal crypto, password and browser data.

According to a Monday report by cybersecurity company Morphisec, RevStealer was previously distributed through GitHub repositories and game-cheat-themed sites but the most notable is a fake “Claude Opus 5 Free Desktop” project that impersonates AI developer Anthropic and promises free access to Claude.

The researchers noted that the malware is designed to leave few traces and searches browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots and selected documents. RevStealer also targets over 50 cryptocurrency wallets.

Read More:  What Happened In Crypto Legal News This Week

The malware checks whether the machine looks like a real user device before unlocking its malicious payload, looking at available memory, the number of processor cores, hostname, username and graphics hardware. It also monitors for the debugging delays typical of malware analysis environment.

If RevStealer detects anything out of the ordinary, it does not move on to the next stages of infection and malicious activity. If the system passes those checks, the payload is decrypted, stored under a random name and covertly executed.

Read More:  Binance Runs Phishing Attacks on Staff to Fight Social Engineering

The report follows the discovery by Russian cybersecurity company Kaspersky of a new malware framework targeting cryptocurrency investors called OkoBot, which can harvest crypto wallet files, browser data and user credentials, inject malicious extensions and capture wallet application windows to steal assets.

Related: Microsoft warns users of ‘Crypto Clipper’ malware spread via USB drives

Read More:  Bitmine Buys 28k ETH, Completes 97% of Treasury Accumulation Goal

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
Facebook Comments Box

LATEST POSTS

15 BTC recovered, LP terms pending

Cross-chain protocol Symbiosis said it recovered approximately 15 BTC after an attacker exploited its native Bitcoin Bridge, but affected liquidity providers still lack compensation terms...

Coinbase and Moov bring stablecoin payments to banks

Coinbase’s new partnership with payments platform Moov gives community banks and credit unions a route to offer stablecoin services through the financial relationship they already...

Most Popular

spot_img