BlockBeats News, September 1st, cybersecurity company Morphisec reported that a malicious program disguised as Anthropic's Claude desktop application is spreading the Windows malware RevStealer. The attackers are using the name "Claude Opus 5 Free Desktop" to lure users to download and install the malware.
It is reported that RevStealer can steal browser passwords, cookies, password manager data, VPN and remote access configurations, instant messaging data, screenshots, and specific documents, and targets over 50 types of cryptocurrency wallets. The malware also has anti-analysis mechanisms that can determine if it is in a real user environment by checking device memory, CPU core count, username, hostname, GPU, etc. If it detects a debugging or virtualized environment, it may halt further malicious activities.
Morphisec stated that RevStealer has previously spread through GitHub repositories and websites related to game cheats. Researchers remind users to avoid downloading AI applications like Claude from unofficial sources, especially being cautious of installation programs claiming to offer a "free advanced version" or "cracked version."

