S&P 5007,631.47▼0.7% Nasdaq26,099.77▼1.0% Dow52,766.88▼0.8% Russell 2K2,920.13▼1.2% 10-Yr4.80%+4bp VIX16.34+1.42 WTI$90.79▲5.9% Gold$4,376.80▼1.2% EUR/USD1.160▼0.2% BTC$77,352▼1.5% Nikkei66,312▲0.3%
At close · Wed, Sep 2, 2026
Daily Market Updates.

Crypto

HomeCryptoMarket StructureFake Claude desktop app spreads crypto-stealing malware

Fake Claude desktop app spreads crypto-stealing malware

The Windows RevStealer malware targets more than 50 crypto wallets and also harvests browser and password-related data from infected devices.

A fake Claude desktop application is reportedly being used to distribute RevStealer, a Windows malware strain designed to steal crypto and sensitive account information. According to Cointelegraph, the campaign has targeted over 50 cryptocurrency wallets in addition to browser data and credentials.

Cybersecurity firm Morphisec said RevStealer was previously spread through other online channels, including GitHub repositories and game-cheat-themed sites, but its most prominent lure imitates an AI offering called “Claude Opus 5 Free Desktop.” The researchers described the fake app as impersonating Anthropic and promising free access to Claude.

The report says the malware is built to leave few traces, searching browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots, and selected documents. It also performs checks to confirm the victim device resembles a real user environment, including memory, processor cores, hostname and username, and graphics hardware.

If the checks appear normal, Cointelegraph reported that the payload is decrypted, stored under a random name, and executed covertly. The article also links the development to earlier work by Kaspersky on OkoBot, a malware framework aimed at cryptocurrency investors that can harvest wallet files and browser data, inject malicious extensions, and capture wallet application windows to steal assets.

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.