Fake Claude app conceals RevStealer payload
Cybersecurity company Morphisec reported on Aug. 31 that RevStealer is being delivered through a trojanized Electron application presented as Claude Opus 5 Free Desktop, which uses Anthropic's branding and offers free access to its paid artificial intelligence model. Before appearing under the Claude name, the malware was distributed through GitHub repositories and websites advertising video game cheats.
The download arrives as an archive of about 101 megabytes containing a 64-bit Electron application. Although victims expect a working Claude interface, the program opens no visible window and instead prepares an encrypted native payload in the background. RevStealer's loader stores the payload as an AES-256-CBC-encrypted resource inside the application. After clearing its initial checks, it decrypts the file, writes it under a random name in the Windows AppData directory, and launches the malware without displaying a window.
At the same time, the loader attempts to add the user's AppData folder to the Microsoft Defender exclusion list. The process is designed to limit the evidence left on the device while allowing the malware to collect and transmit information quickly. Once running, RevStealer resolves Windows application programming interfaces without using a standard import table, making it harder for security products to detect its activity.
RevStealer checks the computer before running
Rather than immediately releasing its main payload, RevStealer first examines the computer for signs that security researchers are watching it. The loader requires at least 2 gigabytes of physical memory, two logical processor cores, and a recognized graphics adapter. Hostname and username checks compare the device against a blocklist associated with research systems.
A separate timing test measures the delay around a JavaScript debugger instruction, wiping the malware's encoded string table when execution pauses for more than about 100 milliseconds. The native stage conducts another 10 checks that produce a weighted anti-virtual-machine score. It also examines the computer's language settings and shuts down on systems configured for Russian, Ukrainian, and several Central Asian languages.
Automated analysis faces another barrier through a CAPTCHA window, which requires interaction before the infection can continue. If the device fails one of the early checks, the loader does not decrypt or expose the payload, leaving researchers with less malicious activity to examine. Morphisec also identified 14 indirect system-call wrappers that allow the malware to reach the Windows kernel while avoiding exported functions commonly monitored by security products.
RevStealer targets crypto wallets and account sessions
On an accepted device, RevStealer searches browser databases, encryption keys, and extension storage for information that can provide access to online accounts. The collection list includes Windows Credential Manager, 12 password managers, more than 50 cryptocurrency wallets, and browser session cookies. The malware also looks for VPN configurations, remote-access credentials, clipboard contents, messaging application data, selected documents, screenshots, game launchers and OBS streaming profiles.
Information collected from each source is placed in an encrypted, typed record before being sent to the operator's command-and-control server. Stolen browser cookies can expose an account even when the owner uses multi-factor authentication. If a valid session has already passed the login process, a criminal may be able to reuse the cookie instead of supplying the victim's password and second authentication factor.
RevStealer can also recover an alternative server address from a smart contract on the Polygon blockchain when its main command-and-control server becomes unavailable. The method lets its operators change infrastructure without rebuilding and redistributing the malware. Unlike malware that creates scheduled tasks or startup entries to remain on a computer, RevStealer does not establish persistence. The program collects the available information, sends it to its operators, and removes itself in a single short burst of theft.
Fake software remains a common crypto malware lure
The Claude impersonation follows several campaigns in which attackers packaged credential-stealing tools as familiar applications, entertainment files, or software updates. In August, fake downloads of a popular movie were delivering Lumma Stealer through Windows executable files disguised as 1080p, WEBRip, and Blu-ray movie releases. The malware could collect cryptocurrency wallet data, saved passwords, payment information, browser cookies, and remote-desktop credentials.
A separate July campaign used lookalike meeting pages and compromised Telegram accounts to target crypto workers. North Korea-linked operators scanned browsers for Ethereum and Solana wallets before presenting some victims with false video conferencing updates. The meeting campaign covered both Windows and macOS devices. On Windows, its PowerShell loader added a Microsoft Defender exclusion, while the macOS version collected system information and Chrome master keys from Apple's Keychain.
For crypto users, the RevStealer campaign underscores the importance of downloading software only from official sources. The malware's anti-analysis features mean that by the time a detection system produces an alert, the credentials, cookies and wallet material may already be gone. Users should verify any download through official channels, avoid GitHub repositories that promise free access to paid AI tools, and use hardware wallets for storing significant cryptocurrency holdings rather than keeping all assets in browser-extension wallets that RevStealer and similar malware can compromise.































.jpg)