Fake Claude desktop app spreads crypto-stealing malware

Summary

A fake “Claude Opus 5 Free Desktop” app is being used to spread RevStealer, a Windows malware strain focused on stealing crypto and login data. The malware has also appeared in GitHub repos and game-cheat-themed sites. It targets browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots, selected documents, and more than 50 cryptocurrency wallets. RevStealer uses anti-analysis checks to verify it is running on a real user device by inspecting memory, CPU cores, hostname, username, graphics hardware, and debugging delays. If the system looks suspicious, it stops; otherwise, it decrypts and runs its payload covertly under a random filename.