Skip to content
Live newsroom 126 readers online
Thursday, September 3, 2026 Live Sync: Just now
Breaking'The Planet Is in Uncharted Waters': UN Chief Sounds Alarm as El Nino Intensifies To Historic Strength
Commodities BUY MSFT Stage 2 (Conv: 5/5 | Size: 20%)

Fake Claude desktop app spreads crypto-stealing malware

RevStealer targets more than 50 crypto wallets alongside browser passwords, cookies, messaging data and selected documents. A fake Claude desktop application is reportedly being used to distribute RevStealer, a Windows malware strain built to steal crypto, password and browser data. According to a Monday report by cybersecurity company Morphisec, RevStealer was previously distributed through GitHub […]

By deepak · September 1, 2026 · 2 min read

RevStealer targets more than 50 crypto wallets alongside browser passwords, cookies, messaging data and selected documents.

A fake Claude desktop application is reportedly being used to distribute RevStealer, a Windows malware strain built to steal crypto, password and browser data.

According to a Monday report by cybersecurity company Morphisec, RevStealer was previously distributed through GitHub repositories and game-cheat-themed sites but the most notable is a fake “Claude Opus 5 Free Desktop” project that impersonates AI developer Anthropic and promises free access to Claude.

The researchers noted that the malware is designed to leave few traces and searches browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots and selected documents. RevStealer also targets over 50 cryptocurrency wallets.

The malware checks whether the machine looks like a real user device before unlocking its malicious payload, looking at available memory, the number of processor cores, hostname, username and graphics hardware. It also monitors for the debugging delays typical of malware analysis environment.

If RevStealer detects anything out of the ordinary, it does not move on to the next stages of infection and malicious activity. If the system passes those checks, the payload is decrypted, stored under a random name and covertly executed.

The report follows the discovery by Russian cybersecurity company Kaspersky of a new malware framework targeting cryptocurrency investors called OkoBot, which can harvest crypto wallet files, browser data and user credentials, inject malicious extensions and capture wallet application windows to steal assets.

Related: Microsoft warns users of ‘Crypto Clipper’ malware spread via USB drives

Cointelegraph is committed to providing independent, high-quality journalism across the crypto, blockchain, AI, and fintech industries.

All news, reviews, and analyses are produced with full journalistic independence and integrity. For more details on our standards and processes, please read our Editorial Policy.

Source: Read the original article on cointelegraph.com

Important Legal & Financial Disclaimer

FutureKnowledge is an automated financial intelligence aggregator. The information provided on this website does not constitute investment advice, financial advice, trading advice, or any other sort of advice and you should not treat any of the website's content as such. We are not registered with the SEC, SEBI, or any regulatory agency. Automated AI-generated content may contain errors. Always conduct your own due diligence and consult your financial advisor before making any investment decisions.

© 2026 FutureKnowledge Intelligence. All rights reserved.