Key Points
- Malicious actors are distributing RevStealer malware through a counterfeit “Claude Opus 5 Free Desktop” application on Windows
- The malware compromises more than 50 cryptocurrency wallets and 12 password management applications
- Advanced anti-detection mechanisms help the malware evade security research environments
- After exfiltrating stolen information to remote servers, the malware automatically removes itself from infected systems
- A failover server address is concealed within a Polygon blockchain smart contract
Security firm Morphisec has uncovered a sophisticated malware campaign utilizing a counterfeit desktop application that mimics Anthropic’s Claude AI assistant to deploy the RevStealer information-stealing malware.
Distributed through GitHub, the fraudulent application is branded as “Claude Opus 5 Free Desktop” and leverages Anthropic’s official imagery and design elements to deceive users into believing they’re accessing a premium AI service at no cost.
Upon installation, the application masquerades as legitimate software. However, rather than launching a functional user interface, it operates covertly in the background while initiating its malicious operations.
Advanced Evasion Techniques
RevStealer employs sophisticated detection avoidance strategies before deploying its core payload. The malware conducts comprehensive system reconnaissance to ensure it isn’t operating within a security analysis environment.
The reconnaissance process examines system RAM capacity, CPU core count, GPU specifications, computer name, and active user account. Additionally, it performs timing analysis designed to identify debugging software typically employed during malware examination.
When any system check indicates a research environment, the malware immediately terminates without leaving forensic evidence. The malware also includes geographic targetingāit automatically exits on systems configured with Russian, Ukrainian, or various Central Asian language settings.
An additional layer of protection comes from a CAPTCHA verification screen that demands human interaction before the infection process advances.
After successfully validating the target environment, the encrypted payload undergoes decryption, receives a randomized filename within the Windows AppData directory, and executes without displaying any visible windows.
To further minimize detection probability, the malware attempts to register the AppData directory as an exclusion within Microsoft Defender’s scanning parameters.
Stolen Information Categories
After deployment, RevStealer initiates comprehensive data harvesting operations targeting browser credentials, stored authentication information, and cryptocurrency wallet storage files. The malware’s target list encompasses more than 50 different cryptocurrency wallet applications and 12 password management solutions, alongside browser session cookies, VPN configuration files, instant messaging application data, screen captures, and document files.
Compromised browser session cookies represent a particularly severe security risk, enabling threat actors to hijack authenticated sessions and bypass two-factor authentication requirements by reusing active sessions without requiring password credentials.
The harvested information undergoes encryption and packaging before transmission to command-and-control infrastructure. In situations where the primary server becomes unavailable, RevStealer retrieves alternative server coordinates from a smart contract deployed on the Polygon blockchain network.
In contrast to persistent malware variants, RevStealer doesn’t maintain a permanent presence on compromised systems. After completing data collection and exfiltration, it executes a self-removal routine. Morphisec researchers characterized this approach as a “single short burst of theft.”
This attack campaign aligns with established patterns of cybercriminals leveraging counterfeit applications to distribute credential-harvesting malware. In July, comparable malicious software was embedded in fabricated video conferencing pages specifically designed to target cryptocurrency industry professionals. Kaspersky researchers separately documented another threat framework designated OkoBot that employs fraudulent wallet recovery interfaces to capture seed phrase information.
In May 2025, United States Department of Justice officials disclosed that another malware-as-a-service platform, LummaC2, had facilitated no fewer than 1.7 million data compromise incidents before law enforcement agencies initiated disruption operations against its supporting infrastructure.


