Follow

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Subscribe

RevStealer Malware Fakes Claude Desktop App to Target Crypto Wallets

RevStealer malware Claude RevStealer malware Claude

Morphisec has published a threat analysis exposing RevStealer malware Claude impersonation tactics: a trojanised Electron application distributed via a GitHub repository named ‘Claude-Opus-5-Free-Desktop’ that mimics Anthropic’s AI platform and offers a download file called ClaudeOpus5-desktop.zip, approximately 101 MB, complete with screenshots and model comparison charts to sell the fiction.

The campaign, detailed in Morphisec’s RevStealer threat analysis authored by Shmuel Uzan and dated August 2026, is one of several delivery vectors the malware has used, alongside GitHub repositories and game-cheat-themed sites. The Claude impersonation is the most polished of these.

RevStealer Malware and the Claude Impersonation

Once executed, RevStealer goes after more than 50 cryptocurrency wallets alongside browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots and selected documents.

The malware’s evasion architecture is layered. According to Help Net Security‘s coverage of the Morphisec findings, RevStealer resolves Windows APIs without a normal import table, keeps its configuration encrypted until the moment of use, routes kernel calls through indirect system calls to slip past user-mode hooks, and streams stolen data directly to its server rather than staging a local archive. It then deletes itself after execution.

The Morphisec report adds a detail that makes this strain particularly resilient: RevStealer uses blockchain-based command-and-control failover, meaning defenders cannot simply sinkhole a domain to cut off the operator’s connection to infected machines.

Before unlocking its payload, the malware runs a victim-profiling check. It examines available memory, processor core count, hostname, username and graphics hardware, and monitors for the timing delays typical of sandbox or analysis environments. If anything looks off, execution halts. Only on a system that passes those checks does the payload decrypt, write itself under a randomised filename and run covertly.

OkoBot Broadens the Threat Landscape for Crypto Holders

The RevStealer campaign surfaces alongside a separate, longer-running operation. Kaspersky‘s Global Research and Analysis Team (GReAT) identified the OkoBot framework in January 2026; the campaign had been active for more than a year before that and remained ongoing as of July 2026.

OkoBot comprises more than 20 malicious payloads and implants and has reached hundreds of victims across more than 25 countries. The highest concentrations of affected users are in Brazil, Vietnam, Canada, Mexico and Türkiye, per Kaspersky’s data.

The framework’s tooling is specific to crypto infrastructure. Kaspersky’s Securelist deep-dive details a tool called TookPS that exfiltrates seed phrases, a module called OkoSpyware that monitors Chromium-based browsers and deploys additional stealers including Rilide, and implants injected directly into Trezor Suite, Ledger Wallet and Ledger Live processes to capture seed phrases at the application layer. Kaspersky’s investigation also notes that developers appear to be among the campaign’s primary targets, based on observed infection vectors.

Taken together, both campaigns illustrate a shift in crypto-targeting malware: less reliance on phishing pages, more investment in convincing software packaging, anti-analysis logic and resilient C2 infrastructure. For anyone running self-custody setups, the attack surface is the desktop application layer itself.

The Morphisec report includes SHA-256 hashes for the known RevStealer variants; wallet operators running endpoint monitoring should update their threat-intelligence feeds accordingly.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use