Fake Claude App Targets 50+ Crypto Wallets with Revstealer

Morphisec reported that a fake Claude desktop application is distributing RevStealer malware to steal data from over 50 cryptocurrency wallets. The trojanized Electron app uses anti-analysis techniques and language filters to evade detection on Windows systems.

Listen to Article — 5 min
Follow Our News on Google
Be instantly informed of developments.
Add as a preferred source on Google

A trojanized desktop application masquerading as a free version of Anthropic’s Claude AI has emerged as a sophisticated vector for distributing RevStealer malware, specifically engineered to compromise over 50 cryptocurrency wallets, password managers, and web browsers on Windows systems. Security researchers at Morphisec revealed that this deceptive software, branded as “Claude Opus 5 Free Desktop,” exploits high demand for artificial intelligence tools to lure victims into installing unverified binaries that silently harvest sensitive digital assets and credentials.

Leveraging AI Hype for Malware Distribution

The threat campaign marks a significant escalation in how cybercriminals exploit technological trends to bypass user skepticism. According to Morphisec Threat Labs, the malware was previously distributed through GitHub repositories and websites advertising video game cheats, but the shift to a Claude-branded package represents a more targeted and socially engineered approach. By leveraging the prestige and utility of Anthropic’s paid AI models, the attackers create a plausible reason for users to download and execute a 101-megabyte archive. The deception is carefully crafted to appear legitimate, offering “free access” to a premium paid service, a common tactic used to lower the guard of both casual users and technical professionals.

The initial payload is delivered as a 64-bit Electron application. Despite its large size, which often signals a legitimate development environment to unsuspecting users, the program does not open a visible interface. Instead, it operates entirely in the background, preparing an encrypted native payload while maintaining a low profile to avoid detection by standard heuristic scanners.

Deep Dive into RevStealer’s Anti-analysis Evasion

The technical architecture of RevStealer is designed to frustrate automated analysis and manual reverse engineering efforts. The loader stores the malicious payload as an AES-256-CBC-encrypted resource within the application. Once initial checks are passed, the malware decrypts the file, writes it under a random name in the Windows AppData directory, and launches without displaying a window. Crucially, the loader attempts to add the user’s AppData folder to the Microsoft Defender exclusion list, a move intended to limit forensic evidence and allow rapid data exfiltration.

Before releasing its main payload, the malware conducts rigorous environmental checks to ensure it is running on a compromised victim machine rather than a sandbox or research environment. The specific technical parameters identified by Morphisec include:

  • Minimum System Requirements: 2GB of physical memory and two logical processor cores
  • Graphics Adapter Check: Recognition of a valid graphics adapter is mandatory
  • Hostname and Username Verification: Comparison against a blocklist of known research systems
  • Timing Attack Mechanism: Measuring delay around a JavaScript debugger instruction
  • Wipe Condition: Encoded string table is wiped if execution pauses for more than 100 milliseconds

The native stage of the infection performs an additional 10 checks that generate a weighted anti-virtual-machine score. The malware also examines the computer’s language settings, shutting down entirely on systems configured for Russian, Ukrainian, and several Central Asian languages, likely to avoid attention in regions with active threat intelligence sharing.

Hurdles for Automated Security Tools

Security teams face additional barriers in detecting this specific strain of RevStealer. The malware employs a CAPTCHA window that requires human interaction before the infection can continue, effectively halting automated sandbox analysis. If a device fails any of the early environmental checks, the loader refuses to decrypt or expose the payload. This results in minimal malicious activity being left on the device, leaving researchers with limited data to examine and significantly increasing the time and resources required to fully characterize the threat.

Malware Component Technical Function Evasion Technique
Electron Loader Decrypts AES-256-CBC payload Adds AppData to Defender exclusion list
Native Payload Steals crypto wallet data Weighted anti-VM score calculation
Initial Checks Verifies victim environment Timing test on debugger instructions
Language Filter Prevents execution in specific regions Shuts down on RU, UK, and Central Asian locales

How Does the Fake Claude App Install Revstealer Malware?

The malware is distributed as a 101-megabyte archive containing a 64-bit Electron application branded as “Claude Opus 5 Free Desktop.” Upon execution, the program opens no visible window but instead decrypts an AES-256-CBC-encrypted payload in the background, writing it to the Windows AppData directory under a random name to launch the RevStealer malware.

Which Cryptocurrency Wallets Are Targeted by This Specific Malware Strain?

RevStealer is designed to steal data from more than 50 different cryptocurrency wallets, along with password managers and web browsers. The malware specifically targets Windows computers, focusing on harvesting private keys and credentials stored in these applications to facilitate theft of digital assets.

What Technical Measures Does Revstealer Use to Avoid Detection?

The malware employs a multi-layered evasion strategy, including a weighted anti-virtual-machine score, hostname and username blocklists, and a timing test that measures debugger delays. It also includes a language filter that shuts down the malware on systems set to Russian, Ukrainian, or several Central Asian languages, and uses a CAPTCHA window to block automated analysis.

Why Are Attackers Using Claude Branding for Malware Distribution?

Attackers are leveraging the high public interest and demand for Anthropic’s paid AI models to encourage users to install unverified software. By offering “free access” to a premium tool, they exploit social engineering tactics to lower user skepticism, making the malicious download appear like a legitimate and valuable resource.

What Should Users Do If They Have Downloaded the Fake Claude App?

Users who suspect they have downloaded the fake Claude app should immediately disconnect the device from the network and run a comprehensive security scan with up-to-date antivirus software. It is critical to change all passwords, enable multi-factor authentication for crypto wallets, and move any significant digital assets to a new, secure wallet that has never been connected to the compromised device.

This article is provided for informational and educational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice. The digital asset market is highly volatile, speculative, and subject to rapid regulatory changes. While we strive to ensure the accuracy of the information presented, market conditions change quickly, and data may become outdated. You are solely responsible for your own research (DYOR) and financial decisions. ATHPost, its owners, and its authors assume no liability whatsoever for any direct or indirect financial losses, liquidations, or damages arising from the use of this content.