TLDR
- A fake “Claude Opus 5 Free Desktop” app is spreading RevStealer malware on Windows
- RevStealer targets over 50 crypto wallets and 12 password managers
- The malware runs system checks to avoid detection in research environments
- It collects data and sends it to a remote server before deleting itself
- A backup server address is hidden in a smart contract on the Polygon blockchain
Cybersecurity company Morphisec has revealed that a fake desktop application impersonating Anthropic’s Claude AI is being used to distribute a malware strain called RevStealer.
🚨ALERT: If you use Claude, you could LOSE your crypto to malware without ever knowing you were hacked.
The campaigns targeting Claude users spread infostealers that silently grab passwords and browser data, putting exchange logins and hot wallets directly at risk.
One user got… pic.twitter.com/5OTIf64pdl
— Coin Bureau (@coinbureau) August 30, 2026
The fake app is called “Claude Opus 5 Free Desktop” and is hosted on GitHub. It uses Anthropic’s branding to trick users into installing it by promising free access to a paid AI model.
When downloaded, the file appears as a normal desktop application. But instead of opening a working interface, it runs silently in the background and begins preparing a malicious payload.
How the Malware Avoids Detection
RevStealer does not immediately release its payload. It first checks the device to make sure it is not being watched by security researchers.
The malware checks for available memory, processor cores, graphics hardware, hostname, and username. It also runs a timing test to detect debugging tools commonly used in malware analysis.
If the system fails any of these checks, the malware stops and leaves no trace. It also shuts down on devices set to Russian, Ukrainian, or several Central Asian languages.
A CAPTCHA window adds another barrier, requiring user interaction before the infection can continue.
Once the device passes all checks, the payload is decrypted, saved under a random name in the Windows AppData folder, and executed without any visible window.
The malware also tries to add the AppData folder to Microsoft Defender’s exclusion list to reduce the chance of detection.
What RevStealer Steals
Once running, RevStealer searches for browser data, saved passwords, and crypto wallet files. It targets over 50 cryptocurrency wallets and 12 password managers, along with browser cookies, VPN configs, messaging app data, screenshots, and documents.
Stolen browser cookies can allow criminals to access accounts even when two-factor authentication is enabled, because an active session can be reused without a password.
All collected data is packaged into encrypted records and sent to a command-and-control server. If that server goes offline, RevStealer can retrieve a backup address from a smart contract on the Polygon blockchain.
Unlike many malware strains, RevStealer does not stay on the device. It collects what it can, sends the data, and removes itself. Morphisec called it a “single short burst of theft.”
This campaign follows a pattern of attackers using fake software to deliver credential stealers. In July, similar malware was hidden in fake meeting pages targeting crypto workers. Kaspersky also recently identified a separate framework called OkoBot that uses fake wallet recovery screens to steal seed phrases.
In May 2025, the U.S. Justice Department said another malware service, LummaC2, had been used in at least 1.7 million data theft incidents before federal authorities moved to disrupt its infrastructure.
Stop guessing and start investing with confidence. KnockoutStocks gives you the AI insights, market intelligence, and stock research you need to spot opportunities, cut through the noise, and make smarter investment decisions — all in one powerful platform.
Sign up today and get 50% OFF full access to our premium stock picks.
Simply use coupon code SPECIAL50 at checkout to claim your exclusive discount.







