Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake Coding Tests Impersonate Recruiters to Infect Software Developers
September 1, 2026
Critical Langflow RCE (CVE-2024-34200) Actively Exploited by Attackers
September 1, 2026
Five Hackers Plead Guilty to ATM Jackpotting Attacks
September 1, 2026
Home/Threats/RevStealer Malware Hides in Fake Claude Opus 5 App to Steal Passwords, Crypto
Threats

RevStealer Malware Hides in Fake Claude Opus 5 App to Steal Passwords, Crypto

Key Takeaways A new campaign leverages a fake “Claude Opus 5” desktop application to distribute RevStealer malware. RevStealer targets Windows users, aiming to steal passwords, browser...

David kimber
David kimber
September 1, 2026 3 Min Read
4 0

Key Takeaways

  • A new campaign leverages a fake “Claude Opus 5” desktop application to distribute RevStealer malware.
  • RevStealer targets Windows users, aiming to steal passwords, browser data, and cryptocurrency wallet information.
  • The malware employs anti-analysis techniques, including environmental checks and hidden API calls, to evade detection.
  • Over 50 cryptocurrency wallets are targeted, making this a significant threat to digital assets.
  • Victims are lured through seemingly legitimate GitHub projects offering free access to paid AI models.

Cybercriminals are exploiting the high demand for artificial intelligence tools by distributing RevStealer, a potent Windows information-stealing malware, disguised as a desktop application for the unreleased “Claude Opus 5” AI model. This sophisticated campaign aims to compromise user credentials, sensitive browser data, and cryptocurrency holdings.

Table Of Content

  • Key Takeaways
  • RevStealer’s Broad Data Theft Capabilities
  • Deceptive Delivery and Evasion Tactics
  • Silent Theft and Defensive Steps

The attackers have created a deceptive GitHub project titled “Claude Opus 5 Free Desktop,” offering what appears to be free access to a premium AI service. This tactic capitalizes on users’ desire for cutting-edge AI, prompting them to download a seemingly legitimate software archive that, in reality, delivers the RevStealer payload.

Researchers at Morphisec said in a report that the RevStealer malware has also been observed in other campaigns, notably distributed through websites promoting game cheats. This demonstrates the adaptability of the threat actors, who can repurpose the malware with different lures to target a broader audience seeking unverified software.

RevStealer’s Broad Data Theft Capabilities

The impact of a RevStealer infection extends far beyond simple password compromise. The malware is engineered to systematically harvest a wide array of personal and financial information. This includes data from browser databases, session cookies, records from password managers, VPN and remote access configurations, messaging application data, screenshots, and specific document types.

A critical focus of RevStealer is its ability to target over 50 different cryptocurrency wallets. This capability means that a successful infection could lead to the irreversible theft of digital assets, as stolen funds are often impossible to recover once transferred by the attackers.

Deceptive Delivery and Evasion Tactics

Upon execution, the initial 101 MB Electron application, posing as the Claude Opus 5 client, does not present a functional user interface. Instead, it initiates a series of checks to determine if it is running on a genuine user device or within a sandboxed analysis environment. This anti-analysis technique is a hallmark of the campaign, designed to thwart security researchers and automated detection systems.

The loader meticulously examines system parameters such as available memory, the number of processor cores, hostname, username, and graphics hardware. It also monitors for any delays that might indicate debugging activities. Should the environment appear automated or suspicious, the malware will withhold its malicious payload. This approach mirrors other fake AI tool campaigns that exploit trusted-looking code repositories rather than relying on more easily identifiable malicious attachments.

If the system passes these initial checks, the program proceeds to decrypt an AES-256-CBC encrypted payload embedded within its resources. This component is then written to a randomly named folder within the user’s AppData directory and executed silently, without any visible window. Crucially, the malware attempts to delete its staging file to minimize its footprint. Researchers also noted an effort to add the user’s AppData directory to Microsoft Defender exclusions, further demonstrating its evasive nature. The native component also conducts additional virtual machine checks, terminates if certain regional language settings are detected, and presents a CAPTCHA to hinder automated analysis. This multi-layered approach ensures that even if one collection method fails, the malware can continue its data exfiltration process.

Silent Theft and Defensive Steps

RevStealer is designed for stealth. It collects stolen information in small, encrypted records and transmits it without creating large, easily detectable archives on the compromised disk. The malware employs covert Windows API resolution and indirect system calls to bypass common security monitoring mechanisms. This method of targeting browser sessions and wallet data echoes previous campaigns involving <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/ad805aaa-67ab-444f-8573-9f0d05d38d22/Hackers-Hide-RevStealer-Inside-Fake-Claude-Opus-5-App-to-Steal-Passwords-and-Crypto.pdf?AWSAccessKeyId=ASIA2F3EMEYEZ7GG3U5Z&Signature=99KMLOurb%2BUg3TfaOAhSOKI4oV0%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEOH%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIG%2BQBm86JISG2gSsR1cefh%2FmfuVgys0bYFMk2SD0GYfAAiBPHBzrcI%2FvDY8JSpBWiqgwvga2dcuQYtHRTRbqgtB3pyr8BAip%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIM8u9Nv%2FrmD3hCWDRKKtAEouptYZzaAdoJmZODM0eQ3b4o%2BziDCszJGRKyp82Dep%2Fjt%2FkLloy3sTisSpUIQDIizzBQ%2BUUhvDlFSPlUtFgqeIdNcO7F4mo1Z3hIdmObr6TgyCDj0G5lCWzF0H89zLvw9VBDXHeQaUJLwexjxtqzvpsHtIFff6dAr5jE9mchwEQ0klOPWCm4AO%2Bc%2FsDD7RH2wpS8M1zTmc0rxHCzMTAwMqXbh1G%2BKVALl%2FKdjRlbkbWdb%2BbtJGGz7loWil%2FXQa7Ib8RObaUIUFjC4y8HGeGUQwkHbRzl282gBaNgU4T7iAlT8x35fhTj90DuYz7Vx1eQT5EphKTbCfLPAGh5%2FTH6OGrJFabNtzph8MDnByQlOmw03aNIDz5HMSF0VBKrryZedZVm6RFrbVqbRBeVOur20Bcpr5UO2zefgzUrdAsK50GEx6%2FRu31tqi0YIm9Dgo4FmCgX1SJ8DqvL98emz2VgoWdtGkVteWs1voMJwEbKv5UJkAdxKgjDr8zxccEFt7S2REnlvPUpESwkM40r63GK%2BilZjZkNmlsAKHF%2B0fyDElFssSga8K73MlaAlDpMon4AXpJdDX9n%2BbAvg6%2Fzs%2BRpTWVfwi6IMdlEFKhF1FHaKaJSWiVhgxPnSqX%2BHhEWSyl%2FR5GLYrUGKWwUHiHYq7RO5DyOYZM1i%2BKiAN1Add53xoGZ3op0oyZZZpA8glBmqei7FduSNZX9Bnmldii4JxOl0fDwprAbeV25qV4Rmlzs7hZBNDC3dY2XJdr3iwiji7c4onSMJiisECEw19cme8JcBDCbl9rUBjqZAToYaLKGgseJG0Q17ZAND8yqgqxBtRofswUg812uegf3nzTQG4NzmmRpgRh11W5NlZWnBrUkDglTTqIidJxPnhlKGOb

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Silent Windows Backdoor Activated by Secret Trigger

Next Post

Critical Microsoft Exchange RCE Vulnerability Gets Public PoC

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Microsoft Teams Vulnerability Lets Attackers Impersonate Users
September 1, 2026
Critical JFrog Artifactory Auth Bypass CVE-2023-46233 Lets Attackers Gain Admin Access
September 1, 2026
21,000+ Microsoft Exchange Servers Exposed to Critical CVE-2026-62911 Exploits
September 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us