RevStealer Malware Masquerades as “Claude Opus 5 Free Desktop,” Threatening Crypto Wallets and Sensitive Data
The rapid ascent of advanced AI models has unfortunately created new avenues for cybercriminals. Cybersecurity firm Morphisec Threat Labs recently unveiled a sophisticated threat: a malicious Windows application masquerading as a “Claude Opus 5 Free Desktop” tool. This imposter app, in reality, harbors RevStealer, a potent information-stealing malware designed to pilfer cryptocurrency wallets, browser credentials, password manager data, and a host of other sensitive user information. Its distribution has been traced to GitHub repositories and illicit game-cheating websites, highlighting its insidious reach.
Deception at Its Core: Exploiting AI Popularity
Anthropic officially launched the legitimate Claude Opus 5 AI model on July 24th this year. Capitalizing on the model’s high profile and the enticing promise of “free access to a premium model,” attackers meticulously crafted a counterfeit application. Users are lured into downloading a seemingly innocuous 101 MB compressed file, believing it to be an official desktop client. Upon installation, however, no functional Claude interface appears. Instead, the malicious payload is silently prepared and executed in the background, unbeknownst to the user.
Sophisticated Evasion and Data Exfiltration Tactics
Morphisec’s research indicates that RevStealer employs advanced techniques to evade detection. Before deploying its primary attack modules, the malware first scrutinizes the victim’s system, checking memory, processor cores, username, hostname, and graphics card information. This pre-check aims to determine if the device is a cybersecurity researcher’s sandbox or a virtual analysis environment. Only upon passing these checks does the program decrypt an AES-encrypted payload hidden within the installer. This payload is then written to the Windows AppData directory, and RevStealer attempts to add this folder to Microsoft Defender’s exclusion list, further hindering detection.
Comprehensive Data Harvesting Capabilities
RevStealer’s data collection capabilities are alarmingly extensive, targeting:
- Over 50 types of cryptocurrency wallets
- Approximately 12 password managers
- Windows Credential Manager
- Browser databases and session cookies
- Data from VPNs and remote access tools
- Communication software
- Clipboard contents
- Screenshots
- Specific user files
It’s important to note that the “over 50 wallets” refers to the types of wallets the malware is designed to target, not the number of wallets already compromised.
Stealth and Resilience: Polygon Smart Contract as C2 Backup
In a notable display of sophistication, RevStealer leverages the Polygon smart contract as a backup communication channel. Should its primary command-and-control (C2) servers become unreachable, the malware can read new server addresses directly from the blockchain. Furthermore, the research highlights the malware’s efforts to minimize its footprint: it avoids creating traditional startup entries or scheduled tasks. Instead, after successfully exfiltrating data, RevStealer self-deletes, attempting to shorten its dwell time on infected devices and reduce forensic traces.
Official Guidance and User Precautions
As of September 2nd, Morphisec has not released figures on actual infection numbers or the total value of cryptocurrency losses. The research report also does not suggest that Anthropic’s official programs or infrastructure have been compromised. Users are strongly advised to obtain official Anthropic desktop applications exclusively from Claude’s official download pages. Under no circumstances should users install “free Opus 5” versions advertised on third-party GitHub projects or other unofficial sources.
Users who suspect they may have executed a suspicious installer package should take immediate action:
- Disconnect from the internet immediately.
- Perform a full malware scan on their system.
- On a clean device, reset all passwords.
- Revoke all existing login sessions.
- Evaluate the necessity of transferring assets from hot wallets to entirely new, secure wallets.
Disclaimer: This article provides market information for reference only. All content and views expressed are for informational purposes and do not constitute investment advice. They do not represent the views and positions of the author or BlockBeats. Investors should make their own decisions and trades, and the author and BlockBeats will not bear any responsibility for direct or indirect losses incurred by investors.