Malicious Claude Desktop Clone Deploys Crypto Wallet-Stealing Malware

Generated byAinvest Coin BuzzReviewed byDavid Feng
Thursday, Sep 3, 2026 10:29 am ET3min read
CRWD--
Aime RobotAime Summary

- Morphisec uncovers RevStealer malware campaign via fake Claude AI app, targeting crypto wallets and stealing browser data.

- Malware evades detection through system checks on memory/hardware and halts execution in sandboxed environments.

- Campaign exploits AI tool popularity as social engineering lure, mirroring Sality botnet's 20-year crypto theft via clipboard hijacking.

- Researchers warn users to verify software authenticity and avoid unofficial AI app downloads to prevent data breaches.

  • Cybersecurity firm Morphisec has identified a malicious campaign distributing RevStealer malware via a fraudulent desktop application impersonating Anthropic's Claude AI .
  • The malware targets over 50 cryptocurrency wallets and harvests sensitive browser data, session cookies, and credentials from infected systems .
  • RevStealer employs sophisticated anti-detection mechanisms, including system checks on memory and hardware, to evade sandboxed analysis environments .
  • This threat highlights a growing trend of using popular AI tools as social engineering lures to distribute financial malware to crypto investors .
  • Federal authorities and CrowdStrikeCRWD-- have also recently dismantled the Sality botnet, which utilized clipboard hijacking to steal cryptocurrency for over two decades .

The cybersecurity firm Morphisec has uncovered a sophisticated malware distribution campaign that leverages a fraudulent desktop application titled "Claude Opus 5 Free Desktop." This malicious software impersonates Anthropic, the developer behind the popular Claude AI model, to deceive users into downloading and installing the malware. Anthropic does not offer a free desktop version of its Claude application, making any such offer a clear indicator of malicious intent. The campaign specifically targets users seeking free access to premium AI models, exploiting the high demand for artificial intelligence tools to distribute information-stealing malware.

Once installed on a Windows system, the RevStealer malware performs an extensive sweep of the infected device. It aggressively targets browser databases, session cookies, password-manager records, VPN configurations, and instant messaging data. A critical component of the malware is its ability to identify and steal data from over 50 different types of cryptocurrency wallets. The theft of session cookies is particularly dangerous, as it allows attackers to bypass two-factor authentication and take over accounts without requiring additional verification codes.

To ensure its survival and evade detection by security tools, RevStealer is engineered with advanced anti-analysis features. Before executing its payload, the malware conducts a series of system checks examining available memory, processor core count, hostname, username, and graphics hardware. It also monitors for debugging delays that are typical of sandboxed analysis environments. If any parameter appears suspicious or inconsistent with a genuine user device, the malware halts its operation. Only when all checks pass does the payload decrypt itself, rename its file randomly, and execute covertly.

This campaign follows similar findings by Kaspersky regarding OkoBot, another malware framework targeting cryptocurrency investors by harvesting wallet files and injecting malicious browser extensions. The emergence of these threats underscores a growing trend of using popular AI tools as social engineering lures to distribute financial malware. Researchers emphasize that users must verify software authenticity and avoid downloading AI applications from unofficial sources, particularly those claiming to offer free premium or cracked versions.

How Does RevStealer Evade Security Analysis?

RevStealer's anti-detection mechanisms are designed to mimic genuine user devices and avoid triggering alerts in controlled analysis environments. The malware performs detailed system checks on memory, processor cores, hostname, username, and installed graphics hardware to ensure the machine resembles a real user device rather than a sandbox. It also monitors for debugging delays characteristic of controlled analysis environments. If any suspicious indicators are found, the malware halts infection to avoid detection by security researchers.

When the system passes all checks, the malware payload is decrypted and stored under a random filename. It then executes covertly, ensuring that the infection remains undetected by standard security tools. This approach allows the malware to operate silently on the infected system, harvesting sensitive data and targeting cryptocurrency wallets without raising immediate alarms. The use of random filenames and payload decryption adds an additional layer of complexity for security analysts attempting to analyze the malware's behavior.

What Is the Broader Context of Crypto Theft Threats?

The RevStealer campaign coincides with recent developments in the cryptocurrency theft landscape, including the dismantling of the Sality botnet by federal authorities and CrowdStrike. The Sality botnet, operational for over twenty years, used a clipjacking tool called EggJagger to steal cryptocurrency by silently replacing wallet addresses in user clipboards with attacker-controlled ones. This technique allowed thieves to steal at least 12.1 million rubles, equivalent to approximately $150,000 in digital currency, over an eight-year period.

The Sality botnet operated using a decentralized peer-to-peer architecture, which complicated takedown efforts by eliminating the need for a centralized command server. The disruption was achieved by CrowdStrike researchers identifying a vulnerability in this peer-to-peer protocol. By substituting legitimate peer addresses with company-controlled infrastructure, investigators isolated over 15,000 infected devices from the criminal network. This highlights the persistent threat of clipboard hijacking in the cryptocurrency ecosystem and the effectiveness of coordinated public-private sector interventions.

While Anthropic's Claude offers robust model-level safety through Constitutional AI, it lacks intrinsic data protection for inputs. Enterprise security requires external Data Loss Prevention (DLP) controls across five interaction surfaces: browser, desktop app, MCP connectors, API, and file uploads, to prevent sensitive data leakage. The primary risk lies in the five surfaces where data enters Claude’s context window, with MCP connectors being particularly risky as they allow Claude to autonomously pull data from SaaS tools like Slack, SharePoint, and databases, bypassing traditional proxy-based DLP.

The convergence of AI-driven social engineering and sophisticated malware distribution techniques poses significant risks to cryptocurrency investors. As cybercriminals continue to exploit popular AI tools and trends, users must remain vigilant and verify the authenticity of software before downloading. The theft of session cookies and cryptocurrency wallets through malware like RevStealer underscores the need for robust security measures and awareness of emerging threats in the digital asset space.

The recent takedown of the Sality botnet demonstrates the ongoing efforts of law enforcement and cybersecurity firms to combat cryptocurrency theft. However, the emergence of new malware strains like RevStealer highlights the evolving nature of these threats. Investors and enterprises must adopt layered security strategies, including endpoint protection, browser DLP, and strict verification of software sources, to mitigate the risk of financial loss from malware-driven attacks.

Blending traditional trading wisdom with cutting-edge cryptocurrency insights.

Latest Articles

Stay ahead of the market.

Get curated U.S. market news, insights and key dates delivered to your inbox.

Comments



No comments

No comments yet