A fake cloud desktop application is reportedly being used to distribute RevStealer, a Windows malware strain designed to steal crypto, passwords and browser data.
According to a Monday Report By cybersecurity company Morphisec, RevStealer was previously distributed via GitHub repositories and game-cheat-themed sites but most notably a fake “Claude Opus 5 Free Desktop” project impersonating AI developer Anthropic and promising free access to Claude.
The researchers noted that the malware is designed to trace and search browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots, and selected documents. RevStealer targets more than 50 cryptocurrency wallets.
Before unlocking its malicious payload, the malware checks whether the machine looks like a real user device by looking at available memory, number of processor cores, hostname, username and graphics hardware. It also monitors for typical debugging delays in malware analysis environments.
If RevStealer detects something out of the ordinary, it does not proceed to the next stage of infection and malicious activity. If the system passes those checks, the payload is decrypted, stored under a random name, and executed secretly.
The report follows a discovery by Russian cybersecurity company Kaspersky New malware framework targets cryptocurrency investors Known as OkoBot, it can collect crypto wallet files, browser data and user credentials, inject malicious extensions and capture wallet application windows to steal assets.
Related: Microsoft warns users of ‘Crypto Clipper’ malware spreading via USB drives
