September 01, 13:56

Fake Claude app spreads RevStealer malware

Fake Claude app spreads RevStealer crypto malware

Cointelegraph

A fake Claude desktop application is being used to distribute RevStealer, a Windows malware strain. RevStealer targets more than 50 cryptocurrency wallets. The malware searches for browser passwords and cookies. It also searches password-manager records, VPN settings and remote-access settings. RevStealer collects messaging data, screenshots and selected documents. Morphisec said in a Monday report that the malware previously spread through GitHub repositories and game-cheat-themed websites. The fake project is called "Claude Opus 5 Free Desktop." The project impersonates AI developer Anthropic and promises free access to Claude. RevStealer checks available memory before unlocking its payload. It checks the number of processor cores, the hostname, the username and the graphics hardware. It also monitors for debugging delays associated with malware-analysis environments. If RevStealer detects unusual conditions, it does not continue to later infection stages. If the system passes the checks, the malware decrypts its payload. It stores the payload under a random name and executes it covertly. Kaspersky also discovered OkoBot, a malware framework targeting cryptocurrency investors. OkoBot can harvest crypto wallet files, browser data and user credentials. It can inject malicious extensions. It can capture wallet application windows to steal assets.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.