A fake Claude desktop application is being used to distribute RevStealer, Windows malware designed to steal cryptocurrency, passwords, and browser data. According to cybersecurity company Morphisec, the malware targets more than 50 different cryptocurrency wallets and poses a serious threat to users of AI tools looking for access to advanced language models.
Key threat: A fake project called "Claude Opus 5 Free Desktop" impersonates Anthropic and promises free access to Claude. Installing it delivers RevStealer, which steals data from 50+ cryptocurrency wallets, passwords, cookies, and messages.
RevStealer was previously distributed through GitHub repositories and websites offering game cheats, but the fake "Claude Opus 5 Free Desktop" project has become one of its most notable disguises. Attackers create a convincing imitation of an official Anthropic application and promise users free access to an advanced AI model. The malware is distributed through several channels, including fake repositories with attractive names, game-cheat websites disguised as useful utilities, as well as forums and social media posts containing direct links to malicious files. The attackers rely heavily on social engineering and exploit the rapidly growing interest in AI technologies. Users eager to gain free access to advanced AI models can become easy targets when they ignore basic digital hygiene and download executable files from unverified sources. Attacks may also begin with targeted advertising on social networks, where automated accounts post links to supposedly "leaked" beta versions of neural networks, creating artificial hype and a sense of urgency among potential victims.
RevStealer is designed to minimize obvious traces of its activity and includes mechanisms intended to detect environments commonly used for malware analysis. Before deploying its malicious payload, the program performs a series of checks to determine whether it is running on a real user's computer rather than inside a virtual machine or an analyst's sandbox. The malware can inspect system characteristics such as available RAM, the number of processor cores, hostname, username, and graphics hardware. It may also look for signs associated with automated analysis environments. If the system passes these checks, the payload is decrypted and executed, allowing the stealer to begin collecting information while attempting to remain unnoticed by the victim.
Anti-analysis technique: If RevStealer detects signs of virtualization or a debugging environment, it may terminate execution, making automated malware analysis and detection more difficult.
RevStealer is a comprehensive information stealer with a broad range of targets. The malware is designed to search for data associated with more than 50 cryptocurrency wallets, including desktop applications such as Exodus, Electrum, and Atomic Wallet, browser extensions including MetaMask, Phantom, and Rabby, as well as software associated with hardware wallets such as Ledger Live and Trezor Suite. Beyond cryptocurrency, RevStealer can collect credentials stored by popular browsers and search for other valuable authentication data. Session cookies are particularly dangerous because stolen session information can sometimes allow attackers to access accounts without entering the victim's password again. Depending on the capabilities of a particular malware build, additional information stored on the compromised computer may also become exposed, making the infection a threat not only to cryptocurrency holdings but to the victim's broader digital identity.
Alongside threats such as RevStealer, cybersecurity researchers continue to identify new malware frameworks targeting cryptocurrency users. One example is OkoBot, which has been associated with attempts to collect wallet-related and browser information from compromised systems. Such malware demonstrates how attackers are increasingly interested not only in traditional credentials but also in the software and browser extensions used to manage digital assets.
The emergence of multiple stealer families targeting the same audience creates an increasingly complex threat landscape. Attackers can change malware families, distribution channels, and obfuscation techniques when existing campaigns are detected, making it difficult to rely exclusively on traditional signature-based security tools.
The fake Claude application is part of a wider trend in which cybercriminals exploit the popularity of artificial intelligence. Well-known AI brands make attractive bait because millions of users actively search for desktop clients, new models, beta releases, local versions, and ways to access premium features.
Attackers can imitate services such as Claude, ChatGPT, Midjourney, GitHub Copilot, and popular image-generation or local AI tools. Modern website templates and AI-generated content also make it easier to build convincing fake landing pages. As a result, a fraudulent website may visually resemble the legitimate service extremely closely, while its domain name and download files reveal that it has no connection to the actual developer.
Offers involving supposedly leaked beta versions, cracked subscriptions, unofficial activators, or "free premium" desktop clients should therefore be treated with particular caution.
The most effective defense begins with the source of the software. Applications should be downloaded only through official developer websites or other distribution channels explicitly listed by the developer. Users should carefully check the domain name and, where applicable, verify the digital signature of executable files.
Promises of free access to paid AI products, unreleased models, or premium functionality through an unofficial executable file should be considered a major warning sign. Requests to disable antivirus protection, ignore operating-system security warnings, or add an unknown program to security exclusions are additional reasons to stop the installation immediately.
For cryptocurrency users, hardware wallets can significantly reduce the risk of private keys being extracted directly from a compromised computer. However, they are not a complete defense against malware. Transaction addresses and amounts should always be verified on the trusted display of the hardware wallet before approval, and recovery phrases should never be entered into random websites or unofficial applications.
Fake applications also create significant problems for the companies whose brands are being impersonated. AI developers have to monitor malicious domains, fraudulent repositories, advertisements, and software packages that misuse their names and logos. Removing such content can involve cooperation with hosting providers, domain registrars, search platforms, and other infrastructure providers.
Code signing and clearly documented official distribution channels can help users distinguish legitimate applications from malicious copies. At the same time, attackers constantly modify their files and delivery methods, meaning that security software alone cannot guarantee protection against every newly created variant.
This makes user behavior an important part of the security model. Verifying where an application came from before running it is considerably safer than attempting to determine whether a suspicious program is malicious after it has already been installed.
Fundamental principle: As AI products become more valuable and popular, their names also become more attractive to cybercriminals. Verifying the authenticity and source of software should become a routine step before every installation.
The RevStealer campaign demonstrates how quickly cybercriminals adapt familiar malware distribution techniques to new technological trends. Instead of relying solely on pirated software, game cheats, or suspicious email attachments, attackers can now disguise information stealers as desirable AI applications.
For cryptocurrency users, the consequences can be particularly severe because a single compromised Windows computer may expose wallet-related information, browser credentials, session data, and other sensitive information at the same time.
The safest approach is straightforward: obtain AI software only from official sources, treat unofficial "free premium" applications with suspicion, keep important cryptocurrency keys isolated from everyday computers, and never trust an executable file simply because it displays the logo of a familiar company.
Key takeaway: A familiar AI brand does not make an application legitimate. The source of the software matters far more than its name, interface, or promised features.
