Fake Claude desktop app spreads crypto-stealing malware
A fake Claude desktop app is spreading RevStealer, Windows malware built to drain more than 50 cryptocurrency wallets along with browser passwords, cookies, messaging data, and selected documents. Cybersecurity researchers at Morphisec say the scam impersonates Anthropic through a fake "Claude Opus 5 Free Desktop" download that promises free access to the AI assistant.
The threat sits at the intersection of two fast-moving trends: explosive demand for AI tools and persistent attacks on crypto holders. Anyone hunting for a free desktop version of Claude should treat unsolicited installers as a serious financial risk, not a shortcut to premium software.
Key Takeaways
- RevStealer targets 50+ crypto wallets plus passwords, cookies, VPN settings, and messaging data.
- The fake "Claude Opus 5 Free Desktop" project impersonates Anthropic to lure downloads.
- Malware runs anti-analysis checks and only deploys its payload on machines that look like real user devices.
- RevStealer was previously distributed via GitHub repositories and game-cheat-themed sites.
- Kaspersky recently flagged a separate OkoBot framework also built to steal crypto assets.
What is the fake Claude desktop app scam?
According to a Monday report from Morphisec, attackers are using a counterfeit desktop application to distribute RevStealer. The most notable campaign centers on a project called "Claude Opus 5 Free Desktop," which mimics AI developer Anthropic and advertises free access to Claude.
RevStealer is not new to security researchers. Morphisec notes it has previously appeared in GitHub repositories and on game-cheat-themed websites. The Claude-branded lure is significant because it exploits trust in a widely recognized AI brand at a moment when users actively seek desktop clients for chat assistants.
Anthropic offers official Claude products through its own channels. Any third-party "free desktop" build found on random download pages or repos should be treated as suspicious until verified directly with the vendor.
How does RevStealer steal crypto and personal data?
Once active, RevStealer is designed to leave few traces while harvesting a broad sweep of sensitive material. Researchers say it searches browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots, and selected documents.
The malware specifically targets more than 50 cryptocurrency wallets, making it a direct threat to anyone who stores keys or wallet files on an infected Windows machine. Combined with stolen browser credentials, attackers can potentially access exchange accounts and self-custody tools in a single compromise.
Before unleashing its full toolkit, RevStealer performs environment checks. It inspects available memory, processor core count, hostname, username, and graphics hardware. It also watches for debugging delays typical of malware analysis sandboxes.
If anything looks abnormal, the infection stops. When the system passes those checks, the payload is decrypted, saved under a random filename, and executed covertly. That evasion-first design makes RevStealer harder to catch in lab environments and easier to miss on everyday PCs.
Why should crypto holders take this threat seriously?
Crypto-focused infostealers have become a recurring theme in 2026 security reporting. The Morphisec findings follow Kaspersky's discovery of OkoBot, a separate malware framework that can harvest wallet files, browser data, and credentials, inject malicious browser extensions, and capture wallet application windows to steal assets.
Together, these campaigns underscore that wallet theft no longer depends on phishing links alone. Malware disguised as productivity or gaming software can exfiltrate keys and session data silently. For holders with meaningful balances, a single bad download can outweigh months of market gains.
Stay current on similar scams in our Fintech & Crypto Alerts hub, where we track wallet drains, exchange incidents, and emerging malware lures targeting digital asset users.
How can you avoid downloading fake AI desktop apps?
Security hygiene starts with source verification. Download Claude and other AI tools only from official vendor websites or verified app stores, never from "free premium" mirrors, cracked-game forums, or unfamiliar GitHub repos.
Keep antivirus and endpoint protection updated, avoid running unsigned installers, and be wary of projects that promise paid-tier AI models at no cost. If you already installed a suspicious Claude desktop build, disconnect from the internet, run a full malware scan, rotate passwords from a clean device, and review wallet activity immediately.
For full technical details on RevStealer's behavior and distribution channels, see the original Cointelegraph report citing Morphisec's research.