Malicious Claude Desktop Clone Deploys Crypto Wallet-Stealing Malware

Wait 5 sec.

Key PointsFraudulent “Claude Opus 5 Free Desktop” application distributes RevStealer on Windows systemsMalware compromises more than 50 cryptocurrency wallets and 12 credential management toolsSophisticated evasion tactics bypass security research and analysis environmentsStolen information is transmitted to remote infrastructure before the malware self-destructsFallback command server address is embedded within a Polygon blockchain smart contractSecurity researchers at Morphisec have uncovered a malicious campaign leveraging a counterfeit desktop client mimicking Anthropic’s Claude artificial intelligence assistant to deploy the RevStealer information-stealing malware.ALERT: If you use Claude, you could LOSE your crypto to malware without ever knowing you were hacked.The campaigns targeting Claude users spread infostealers that silently grab passwords and browser data, putting exchange logins and hot wallets directly at risk.One user got… pic.twitter.com/5OTIf64pdl— Coin Bureau (@coinbureau) August 30, 2026Distributed as “Claude Opus 5 Free Desktop” through GitHub repositories, the fraudulent application exploits Anthropic’s brand identity to deceive victims into downloading it under the pretense of accessing premium AI capabilities without charge.Upon installation, the executable masquerades as legitimate software. However, rather than launching a functional user interface, it operates covertly in the background while staging its malicious components.Evasion Techniques and Anti-Analysis MeasuresRevStealer employs sophisticated reconnaissance before deploying its primary functionality. The malware conducts extensive system profiling to verify it isn’t operating within a controlled research environment.System fingerprinting includes enumeration of RAM capacity, CPU core count, GPU specifications, machine hostname, and active user account. Additionally, it performs temporal analysis to identify virtualization or debugging frameworks frequently employed in malware research.Systems that trigger any detection heuristics cause the malware to abort execution without leaving forensic evidence. The malware also terminates on machines configured with Russian, Ukrainian, or various Central Asian language settings.An intermediary CAPTCHA challenge provides an additional layer of obfuscation, necessitating human interaction before proceeding with the infection sequence.After successfully validating the environment, the encrypted payload undergoes decryption, receives a randomized filename within the Windows AppData directory, and launches as a windowless background process.To further evade detection, the malware attempts to register the AppData directory as an exclusion within Microsoft Defender’s scanning parameters.Data Exfiltration CapabilitiesFollowing successful deployment, RevStealer initiates comprehensive data harvesting operations across browser profiles, stored credentials, and cryptocurrency wallet storage. Its targeting scope encompasses more than 50 digital currency wallets and 12 password management applications, supplemented by browser session cookies, VPN configuration files, messaging platform data, screen captures, and document files.Compromised authentication cookies present particular risk, enabling threat actors to hijack active sessions and bypass multi-factor authentication protections through session replay attacks.Harvested information undergoes encryption and compression before transmission to command-and-control infrastructure. In scenarios where primary exfiltration servers become unavailable, RevStealer retrieves alternative connection parameters from a smart contract deployed on the Polygon blockchain network.Distinguishing itself from persistent threats, RevStealer functions as transient malware. Following data exfiltration, it eliminates all traces of its presence from the compromised system. Morphisec characterized this methodology as a “single short burst of theft.”This operation represents a continuation of adversarial tactics leveraging counterfeit applications for credential harvesting. In July, comparable malware was distributed through fabricated video conferencing interfaces specifically targeting cryptocurrency industry professionals. Kaspersky researchers separately documented the OkoBot framework, which utilizes deceptive wallet recovery interfaces to capture seed phrase mnemonics.In May 2025, the U.S. Department of Justice disclosed that the LummaC2 malware-as-a-service platform had facilitated approximately 1.7 million credential theft operations before law enforcement intervention disrupted its operational infrastructure.The post Malicious Claude Desktop Clone Deploys Crypto Wallet-Stealing Malware appeared first on Blockonomi.