Fake Claude Desktop App Used to Steal Crypto and Passwords
Fake AI application spreads RevStealer malware
A malicious desktop application impersonating the Claude AI assistant is being used to spread RevStealer malware. This software is designed to steal sensitive data, including information from more than 50 different cryptocurrency wallets—digital tools used to store and manage blockchain assets.
The fake application, named "Claude Opus 5 Free Desktop," claims to offer free access to AI tools developed by Anthropic. However, researchers report that the project is a trap designed to infect Windows computers with software that steals browser passwords, cookies, and messaging data.
Key details about the RevStealer attack
- Targets over 50 specific cryptocurrency wallets.
- Steals browser cookies, saved passwords, and login records.
- Searches for VPN settings, remote-access credentials, and private documents.
- Uses "anti-analysis" techniques to avoid being detected by security software.
Technical findings from the Morphisec report
According to a report by cybersecurity company Morphisec, RevStealer uses sophisticated methods to stay hidden. Before activating its harmful features, the malware checks the computer’s memory, processor, and graphics hardware. This helps the virus determine if it is running on a real user’s device or a testing environment used by security researchers.
If the malware determines the device belongs to a real user, it decrypts a hidden file and runs it under a random name. This makes it difficult for traditional security programs to track or stop the infection.
Additional malware threats reported by Kaspersky
The discovery of RevStealer follows other recent warnings about security threats to digital asset holders. The cybersecurity firm Kaspersky recently discovered "OkoBot," a malware framework that harvests wallet files and injects malicious extensions into browsers. Additionally, Microsoft has warned users about "Crypto Clipper" malware, which is spread through USB drives to target transaction data.
Risks for AI and cryptocurrency users
Attackers are increasingly using the popularity of AI platforms like Claude to trick people into downloading dangerous software. By promising free access to premium AI features, hackers can convince users to bypass security warnings. This can give attackers full access to financial accounts, private messages, and sensitive personal information.