Key Takeaways
- Fraudulent “Claude Opus 5 Free Desktop” application distributes RevStealer malware on Windows systems
- Malicious software compromises more than 50 cryptocurrency wallets and 12 password management tools
- Advanced evasion techniques help the malware bypass detection in security analysis environments
- Stolen information is transmitted to remote servers before the malware self-destructs
- Fallback command server address is concealed within a Polygon blockchain smart contract
Security research firm Morphisec has uncovered a malicious campaign leveraging a counterfeit desktop application mimicking Anthropic’s Claude AI platform to deploy RevStealer malware.
The fraudulent software, branded as “Claude Opus 5 Free Desktop,” is distributed through GitHub repositories. It exploits Anthropic’s visual identity and reputation to deceive users by offering complimentary access to premium AI functionality.
Upon installation, the executable masquerades as legitimate desktop software. However, rather than launching a functional user interface, it operates covertly in the system background while staging its malicious components.
Sophisticated Evasion Mechanisms
RevStealer employs sophisticated anti-analysis techniques before deploying its primary payload. The malware performs comprehensive system profiling to ensure it isn’t operating within a security research environment.
Environmental checks include scanning system memory capacity, CPU core count, GPU specifications, computer hostname, and active username. Additional runtime analysis tests help identify debugging utilities frequently employed during malware examination.
Systems that trigger these defensive mechanisms cause the malware to terminate immediately without leaving forensic evidence. The threat also refuses execution on machines configured with Russian, Ukrainian, or various Central Asian language settings.
An additional CAPTCHA challenge creates another verification layer, demanding human interaction before proceeding with the infection sequence.
After successfully passing all validation checks, the encrypted payload is unlocked, stored with a randomized filename in the Windows AppData directory, and launched without displaying any interface elements.
To minimize detection probability, the malware attempts to register the AppData directory within Microsoft Defender’s exclusion parameters.
RevStealer’s Data Harvesting Capabilities
Following successful deployment, RevStealer systematically scans for browser credentials, stored authentication data, and cryptocurrency wallet files. Its targeting scope encompasses more than 50 digital currency wallets and 12 password management applications, alongside browser session cookies, VPN configuration files, instant messaging application data, screen captures, and document files.
Harvested browser session cookies present particular danger, enabling attackers to hijack authenticated sessions even when two-factor authentication protects accounts, since valid sessions bypass standard login requirements.
All exfiltrated information is encrypted, organized into structured packages, and transmitted to attacker-controlled command infrastructure. Should the primary server become inaccessible, RevStealer queries a backup server address embedded within a smart contract deployed on the Polygon blockchain network.
Distinguishing itself from persistent malware variants, RevStealer operates as a smash-and-grab threat. It harvests available data, transmits the stolen information, and eliminates all traces of itself. Morphisec characterized this approach as a “single short burst of theft.”
This attack campaign represents the latest iteration of cybercriminals weaponizing counterfeit applications to distribute credential-stealing malware. In July, comparable threats were embedded in fraudulent meeting platforms specifically targeting cryptocurrency industry professionals. Kaspersky recently documented another malicious framework named OkoBot that employs fake wallet recovery interfaces to capture recovery seed phrases.
In May 2025, the United States Department of Justice announced that another information-stealing service, LummaC2, had facilitated approximately 1.7 million data breach incidents before law enforcement agencies disrupted its operational infrastructure.





