Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnAISquareMore
Fake Claude app infects Windows with RevStealer malware targeting crypto wallets

Fake Claude app infects Windows with RevStealer malware targeting crypto wallets

CointurkCointurk2026/09/01 14:21
By:Cointurk

A desktop application posing as the Claude AI assistant is being used to deploy RevStealer, a Windows-based malware designed to steal cryptocurrencies, passwords, and browser data from unsuspecting users.

Malware Mimics User Behavior Checks

Cybersecurity researchers reported that RevStealer incorporates advanced detection evasion techniques before releasing its malicious payload. The software first verifies if the infected device resembles a genuine user environment, evaluating available memory, processor core count, machine hostname, username, and graphics hardware. This vetting process helps the malware determine whether it is running in a research or analysis environment, such as a sandbox.

In addition, RevStealer looks for delays in system responses that are typical of malware analysis setups. These countermeasures are intended to help it avoid detection by cybersecurity tools and human analysts.

RevStealer unlocks its harmful functions only if it determines that the device has all the characteristics of a real user system, while refusing to proceed in controlled analysis settings.

If RevStealer flags any suspicious characteristics, it immediately ceases operations and avoids triggering subsequent infection stages. When a device passes all security tests, however, the malware decrypts the payload, stores it under a randomly generated filename, and executes it in the background without user awareness.

ETH
SOL
BSC
ROBINHOOD
PAY
USDT
RECEIVE
AAPL

Emergence of New Threats Targeting Crypto Investors

The discovery of RevStealer using a fake Claude desktop app follows an earlier report by Kaspersky, a Russian cybersecurity company, which uncovered a separate malware framework named OkoBot. Kaspersky identified OkoBot as a versatile threat that specifically targets cryptocurrency investors, harvesting crypto wallet files, browser data, and user login credentials.

OkoBot can also inject harmful browser extensions and capture the windows of cryptocurrency wallet applications, enabling it to steal digital assets directly from users’ devices.

Mini dictionary: Claude is an AI-powered assistant developed by Anthropic, designed to aid users with tasks such as writing, coding, and research through natural language understanding.

Researchers noted that both RevStealer and OkoBot highlight the increasing sophistication of malware campaigns targeting digital asset holders. Such threats are making it more difficult for ordinary users to distinguish between legitimate software and malicious applications.

Malware Target Primary Functions
RevStealer Windows users, crypto holders Steals crypto, passwords, browser data
OkoBot Crypto investors Harvests wallet files, captures login info, injects malicious extensions

Additional Malware Campaigns Reported

Microsoft recently warned users about the spread of Crypto Clipper malware using USB drives to infect systems. Crypto Clipper is another malware variant that seeks to compromise cryptocurrency wallet data by tampering with clipboard contents and redirecting crypto transactions to attacker-controlled addresses.

These developments emphasize the need for crypto investors to remain cautious and scrutinize software claiming to offer AI or productivity enhancements, especially when downloading from unofficial sources.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!