A fake Claude desktop application has distributed RevStealer malware designed to steal data from more than 50 cryptocurrency wallets, password managers, and web browsers on Windows computers.
Summary
- RevStealer is hidden inside a fake “Claude Opus 5 Free Desktop” application.
- The malware targets more than 50 crypto wallets and 12 password managers.
- System checks prevent the payload from running in some virtual machines and analysis environments.
- RevStealer sends stolen data in encrypted records before deleting itself from the device.
Fake Claude app conceals RevStealer payload
Cybersecurity company Morphisec said in an Aug. 31 report that RevStealer is…







