< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

RevStealer malware targets crypto wallets via fake Claude Opus 5 apps

Security researchers at Morphisec Threat Labs have identified a new Windows-based information stealer named RevStealer. The malware is being distributed through fake desktop applications masquerading as ‘Claude Opus 5 Free Desktop,’ promising free access to Anthropic’s AI model.

Attackers are utilizing GitHub repositories and game cheat websites to host approximately 101 MB ZIP files. Once executed, the application does not provide an AI interface but instead installs the malware in the background. RevStealer is designed to evade detection by checking system specifications to ensure it is not running in a sandbox or virtual analysis environment. It also attempts to add its directory to the Microsoft Defender exclusion list.

The malware targets a wide range of sensitive data, including credentials from over 50 cryptocurrency wallets (such as MetaMask, Phantom, and Coinbase Wallet), approximately 12 password managers (including Bitwarden, 1Password, and LastPass), and Windows Credential Manager. It also collects browser data, session cookies, VPN/FTP credentials, clipboard contents, and screenshots.

To maintain persistence and evade discovery, RevStealer uses Polygon smart contracts as a backup command-and-control communication channel if primary servers are unreachable. The malware is designed to delete itself after exfiltrating data to minimize its forensic footprint on the infected device.

Entities

Anthropic · Claude Opus 5 · Microsoft Defender · Morphisec Threat Labs · RevStealer