RevStealer Malware Hides in Fake Claude Opus 5 App to Steal Passwords, Crypto
Key Takeaways A new campaign leverages a fake “Claude Opus 5” desktop application to distribute RevStealer malware. RevStealer targets Windows users, aiming to steal passwords, browser...
Key Takeaways
- A new campaign leverages a fake “Claude Opus 5” desktop application to distribute RevStealer malware.
- RevStealer targets Windows users, aiming to steal passwords, browser data, and cryptocurrency wallet information.
- The malware employs anti-analysis techniques, including environmental checks and hidden API calls, to evade detection.
- Over 50 cryptocurrency wallets are targeted, making this a significant threat to digital assets.
- Victims are lured through seemingly legitimate GitHub projects offering free access to paid AI models.
Cybercriminals are exploiting the high demand for artificial intelligence tools by distributing RevStealer, a potent Windows information-stealing malware, disguised as a desktop application for the unreleased “Claude Opus 5” AI model. This sophisticated campaign aims to compromise user credentials, sensitive browser data, and cryptocurrency holdings.
Table Of Content
The attackers have created a deceptive GitHub project titled “Claude Opus 5 Free Desktop,” offering what appears to be free access to a premium AI service. This tactic capitalizes on users’ desire for cutting-edge AI, prompting them to download a seemingly legitimate software archive that, in reality, delivers the RevStealer payload.
Researchers at Morphisec said in a report that the RevStealer malware has also been observed in other campaigns, notably distributed through websites promoting game cheats. This demonstrates the adaptability of the threat actors, who can repurpose the malware with different lures to target a broader audience seeking unverified software.
RevStealer’s Broad Data Theft Capabilities
The impact of a RevStealer infection extends far beyond simple password compromise. The malware is engineered to systematically harvest a wide array of personal and financial information. This includes data from browser databases, session cookies, records from password managers, VPN and remote access configurations, messaging application data, screenshots, and specific document types.
A critical focus of RevStealer is its ability to target over 50 different cryptocurrency wallets. This capability means that a successful infection could lead to the irreversible theft of digital assets, as stolen funds are often impossible to recover once transferred by the attackers.
Deceptive Delivery and Evasion Tactics
Upon execution, the initial 101 MB Electron application, posing as the Claude Opus 5 client, does not present a functional user interface. Instead, it initiates a series of checks to determine if it is running on a genuine user device or within a sandboxed analysis environment. This anti-analysis technique is a hallmark of the campaign, designed to thwart security researchers and automated detection systems.
The loader meticulously examines system parameters such as available memory, the number of processor cores, hostname, username, and graphics hardware. It also monitors for any delays that might indicate debugging activities. Should the environment appear automated or suspicious, the malware will withhold its malicious payload. This approach mirrors other fake AI tool campaigns that exploit trusted-looking code repositories rather than relying on more easily identifiable malicious attachments.
If the system passes these initial checks, the program proceeds to decrypt an AES-256-CBC encrypted payload embedded within its resources. This component is then written to a randomly named folder within the user’s AppData directory and executed silently, without any visible window. Crucially, the malware attempts to delete its staging file to minimize its footprint. Researchers also noted an effort to add the user’s AppData directory to Microsoft Defender exclusions, further demonstrating its evasive nature. The native component also conducts additional virtual machine checks, terminates if certain regional language settings are detected, and presents a CAPTCHA to hinder automated analysis. This multi-layered approach ensures that even if one collection method fails, the malware can continue its data exfiltration process.
Silent Theft and Defensive Steps
RevStealer is designed for stealth. It collects stolen information in small, encrypted records and transmits it without creating large, easily detectable archives on the compromised disk. The malware employs covert Windows API resolution and indirect system calls to bypass common security monitoring mechanisms. This method of targeting browser sessions and wallet data echoes previous campaigns involving <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/ad805aaa-67ab-444f-8573-9f0d05d38d22/Hackers-Hide-RevStealer-Inside-Fake-Claude-Opus-5-App-to-Steal-Passwords-and-Crypto.pdf?AWSAccessKeyId=ASIA2F3EMEYEZ7GG3U5Z&Signature=99KMLOurb%2BUg3TfaOAhSOKI4oV0%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEOH%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIG%2BQBm86JISG2gSsR1cefh%2FmfuVgys0bYFMk2SD0GYfAAiBPHBzrcI%2FvDY8JSpBWiqgwvga2dcuQYtHRTRbqgtB3pyr8BAip%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIM8u9Nv%2FrmD3hCWDRKKtAEouptYZzaAdoJmZODM0eQ3b4o%2BziDCszJGRKyp82Dep%2Fjt%2FkLloy3sTisSpUIQDIizzBQ%2BUUhvDlFSPlUtFgqeIdNcO7F4mo1Z3hIdmObr6TgyCDj0G5lCWzF0H89zLvw9VBDXHeQaUJLwexjxtqzvpsHtIFff6dAr5jE9mchwEQ0klOPWCm4AO%2Bc%2FsDD7RH2wpS8M1zTmc0rxHCzMTAwMqXbh1G%2BKVALl%2FKdjRlbkbWdb%2BbtJGGz7loWil%2FXQa7Ib8RObaUIUFjC4y8HGeGUQwkHbRzl282gBaNgU4T7iAlT8x35fhTj90DuYz7Vx1eQT5EphKTbCfLPAGh5%2FTH6OGrJFabNtzph8MDnByQlOmw03aNIDz5HMSF0VBKrryZedZVm6RFrbVqbRBeVOur20Bcpr5UO2zefgzUrdAsK50GEx6%2FRu31tqi0YIm9Dgo4FmCgX1SJ8DqvL98emz2VgoWdtGkVteWs1voMJwEbKv5UJkAdxKgjDr8zxccEFt7S2REnlvPUpESwkM40r63GK%2BilZjZkNmlsAKHF%2B0fyDElFssSga8K73MlaAlDpMon4AXpJdDX9n%2BbAvg6%2Fzs%2BRpTWVfwi6IMdlEFKhF1FHaKaJSWiVhgxPnSqX%2BHhEWSyl%2FR5GLYrUGKWwUHiHYq7RO5DyOYZM1i%2BKiAN1Add53xoGZ3op0oyZZZpA8glBmqei7FduSNZX9Bnmldii4JxOl0fDwprAbeV25qV4Rmlzs7hZBNDC3dY2XJdr3iwiji7c4onSMJiisECEw19cme8JcBDCbl9rUBjqZAToYaLKGgseJG0Q17ZAND8yqgqxBtRofswUg812uegf3nzTQG4NzmmRpgRh11W5NlZWnBrUkDglTTqIidJxPnhlKGOb
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.