Fake Claude Desktop App Spreads RevStealer Crypto Malware
Cybercriminals are exploiting the popularity of Anthropic’s Claude AI as a social-engineering lure, disguising RevStealer malware as an unofficial desktop application. The campaign matters because information-stealing software can expose browser credentials as well as cryptocurrency wallets, allowing attackers to move digital assets quickly and leaving victims with limited options for recovery. Users who seek desktop software outside official distribution channels face the greatest risk.
The latest findings show that a counterfeit app promoted as “Claude Opus 5” targets more than 50 cryptocurrency wallets and harvests sensitive credentials stored in web browsers. RevStealer also performs extensive checks of the host environment, looking for virtual machines, sandboxes and other signs of security analysis before executing its theft routines. The reports did not identify a confirmed victim count, financial losses or a precise start date for the campaign.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →