Cryptocurrency Theft Malware Distributed Through Counterfeit Claude Desktop Application

Cryptocurrency Theft Malware Distributed Through Counterfeit Claude Desktop Application

The RevStealer malicious software compromises over 50 different cryptocurrency wallets while also extracting browser credentials, cookie data, messaging information and specific file types.

Cybercriminals are leveraging a counterfeit version of the Claude desktop application to deploy RevStealer, a Windows-based malicious software designed to extract cryptocurrency holdings, login credentials and web browser information from infected systems.

A Monday analysis published by cybersecurity firm Morphisec reveals that RevStealer had been previously delivered via GitHub code repositories and websites themed around video game cheating tools, though the most significant distribution method involves a fraudulent "Claude Opus 5 Free Desktop" project. This fake project mimics AI development company Anthropic while offering complimentary access to Claude services. The security researchers observed that the malware operates with minimal detection footprints and systematically scans browser database files, cookie stores, password manager repositories, VPN configurations, remote access credentials, messaging application data, screen capture files and specially selected document types. Additionally, RevStealer has the capability to compromise more than 50 different cryptocurrency wallet applications.

The malicious software performs verification checks to determine whether the infected machine resembles an authentic user device prior to activating its harmful payload, examining factors such as system memory capacity, processor core count, computer hostname, user account name and graphics card specifications. The malware also actively monitors for debugging time delays that are characteristic of security analysis and sandbox environments.

When RevStealer identifies any anomalies or suspicious characteristics, it deliberately refrains from advancing to subsequent infection phases and malicious operations. Should the compromised system successfully pass these validation checks, the harmful payload undergoes decryption, gets saved using a randomly generated filename and executes silently in the background.

This security disclosure comes after Russian cybersecurity firm Kaspersky uncovered a separate malware framework designated as OkoBot, which specifically targets cryptocurrency investors and possesses capabilities to extract crypto wallet files, harvest browser information and user authentication credentials, deploy malicious browser extensions and capture wallet application window content for asset theft purposes.