Anthropic: Hackers Hide RevStealer Inside Fake Claude Opus 5 App to Steal Passwords and Crypto

Anthropic: Hackers Hide RevStealer Inside Fake Claude Opus 5 App to Steal Passwords and Crypto

Fake Claude Opus 5 App Distributes RevStealer Malware in AI-Themed Attack

Cybercriminals are exploiting demand for AI tools by distributing RevStealer, a Windows malware designed to steal passwords, browser data, and cryptocurrency wallet information, through a fake "Claude Opus 5 Free Desktop" application. The campaign, uncovered by Morphisec researchers, lures victims into downloading a trojanized Electron-based desktop app from a GitHub repository posing as a legitimate free version of the paid AI model.

The malware has also been deployed via game-cheat websites, demonstrating its adaptability across different social engineering tactics. Once executed, the 101 MB archive does not launch a functional interface instead, it performs environmental checks (memory, CPU cores, hostname, and graphics hardware) to evade detection in automated or virtualized analysis. If the system appears legitimate, it decrypts an AES-256-CBC payload, writes it to a randomly named AppData folder, and attempts to exclude the directory from Microsoft Defender scans.

RevStealer targets over 50 cryptocurrency wallets, browser databases, cookies, password managers, VPN configurations, messaging apps, and screenshots. Data is exfiltrated in small encrypted chunks to minimize detection, using concealed Windows API calls and indirect system calls to avoid security monitoring. The malware self-deletes after execution, leaving minimal traces, and can fetch new command-and-control (C2) addresses via a Polygon smart contract if its primary server is disrupted.

The attack highlights the risks of downloading unverified software, particularly "free" versions of paid AI tools or unofficial repositories. Unlike traditional malware, RevStealer does not rely on persistence mechanisms (e.g., scheduled tasks or startup entries), instead focusing on rapid data theft before removal. Organizations are advised to monitor for unusual browser or wallet access, block execution from high-risk directories, and enforce stronger authentication to mitigate exposure.

Source: https://cybersecuritynews.com/revstealer-inside-fake-claude/

Anthropic TPRM report: https://www.rankiteo.com/company/anthropicresearch

"id": "ant1788258233",
"linkid": "anthropicresearch",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'type': 'Individuals/Organizations'}],
 'attack_vector': ['Trojanized Application', 'Social Engineering'],
 'data_breach': {'data_encryption': 'AES-256-CBC (payload encryption)',
                 'data_exfiltration': 'Yes',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Passwords',
                                              'Browser Data',
                                              'Cryptocurrency Wallet '
                                              'Information',
                                              'Cookies',
                                              'VPN Configurations',
                                              'Messaging App Data',
                                              'Screenshots']},
 'description': 'Cybercriminals are exploiting demand for AI tools by '
                'distributing RevStealer, a Windows malware designed to steal '
                'passwords, browser data, and cryptocurrency wallet '
                "information, through a fake 'Claude Opus 5 Free Desktop' "
                'application. The campaign lures victims into downloading a '
                'trojanized Electron-based desktop app from a GitHub '
                'repository posing as a legitimate free version of the paid AI '
                'model. The malware has also been deployed via game-cheat '
                'websites. Once executed, it performs environmental checks to '
                'evade detection, decrypts an AES-256-CBC payload, and '
                'exfiltrates data in small encrypted chunks to minimize '
                'detection.',
 'impact': {'data_compromised': ['Passwords',
                                 'Browser Data',
                                 'Cryptocurrency Wallet Information',
                                 'Cookies',
                                 'VPN Configurations',
                                 'Messaging App Data',
                                 'Screenshots'],
            'identity_theft_risk': 'High',
            'payment_information_risk': 'High',
            'systems_affected': ['Windows Systems']},
 'initial_access_broker': {'entry_point': ['GitHub Repository',
                                           'Game-Cheat Websites']},
 'lessons_learned': 'The attack highlights the risks of downloading unverified '
                    "software, particularly 'free' versions of paid AI tools "
                    'or unofficial repositories. RevStealer does not rely on '
                    'persistence mechanisms, focusing on rapid data theft '
                    'before removal.',
 'motivation': ['Data Theft', 'Financial Gain'],
 'post_incident_analysis': {'corrective_actions': ['Block execution from '
                                                   'high-risk directories',
                                                   'Enforce stronger '
                                                   'authentication',
                                                   'Monitor for unusual '
                                                   'activity'],
                            'root_causes': ['Downloading unverified software',
                                            'Social engineering tactics']},
 'recommendations': ['Block execution from high-risk directories',
                     'Enforce stronger authentication',
                     'Monitor for unusual browser or wallet access'],
 'references': [{'source': 'Morphisec Researchers'}],
 'response': {'enhanced_monitoring': ['Monitor for unusual browser or wallet '
                                      'access'],
              'third_party_assistance': 'Morphisec Researchers'},
 'title': 'Fake Claude Opus 5 App Distributes RevStealer Malware in AI-Themed '
          'Attack',
 'type': 'Malware Distribution'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.