Cointelegraph
DOGE$0.08304 0.13%
TRX$0.3255 2.30%
LINK$11.47 1.35%
ZEC$858.84 2.82%
ADA$0.2002 1.76%
XRP$1.38 0.32%
ETH$2,454.97 0.37%
BTC$78,378.13 0.09%
XMR$510.22 0.03%
BNB$688.58 0.26%
XLM$0.1791 1.42%
SOL$102.39 1.04%
HYPE$84.10 2.98%
Written by Adrian Zmudzinskistaff writerReviewed by Yohan Yunstaff editor

Fake Claude desktop app spreads crypto-stealing malware

Latest NewsPublishedSep 1, 2026

RevStealer targets more than 50 crypto wallets alongside browser passwords, cookies, messaging data and selected documents.

malware

A fake Claude desktop application is reportedly being used to distribute RevStealer, a Windows malware strain built to steal crypto, password and browser data.

According to a Monday report by cybersecurity company Morphisec, RevStealer was previously distributed through GitHub repositories and game-cheat-themed sites but the most notable is a fake “Claude Opus 5 Free Desktop” project that impersonates AI developer Anthropic and promises free access to Claude.

The researchers noted that the malware is designed to leave few traces and searches browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots and selected documents. RevStealer also targets over 50 cryptocurrency wallets.

The malware checks whether the machine looks like a real user device before unlocking its malicious payload, looking at available memory, the number of processor cores, hostname, username and graphics hardware. It also monitors for the debugging delays typical of malware analysis environment.

If RevStealer detects anything out of the ordinary, it does not move on to the next stages of infection and malicious activity. If the system passes those checks, the payload is decrypted, stored under a random name and covertly executed.

The report follows the discovery by Russian cybersecurity company Kaspersky of a new malware framework targeting cryptocurrency investors called OkoBot, which can harvest crypto wallet files, browser data and user credentials, inject malicious extensions and capture wallet application windows to steal assets.

Related: Microsoft warns users of ‘Crypto Clipper’ malware spread via USB drives

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

More on the subject