Mark RadarMARK RADAR
About
EN
Sign in

Fake Claude Desktop App Spreads RevStealer Crypto Malware

2 reports · First detected 2026-09-02 · Last active 2026-09-02

Cybercriminals are exploiting the popularity of Anthropic’s Claude AI as a social-engineering lure, disguising RevStealer malware as an unofficial desktop application. The campaign matters because information-stealing software can expose browser credentials as well as cryptocurrency wallets, allowing attackers to move digital assets quickly and leaving victims with limited options for recovery. Users who seek desktop software outside official distribution channels face the greatest risk.

The latest findings show that a counterfeit app promoted as “Claude Opus 5” targets more than 50 cryptocurrency wallets and harvests sensitive credentials stored in web browsers. RevStealer also performs extensive checks of the host environment, looking for virtual machines, sandboxes and other signs of security analysis before executing its theft routines. The reports did not identify a confirmed victim count, financial losses or a precise start date for the campaign.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)