← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 1, 2026 · 09:50via CyberPress

Fake Claude Opus 5 App Caught Stealing Passwords and Crypto Wallets

Brief

Cybersecurity researchers have uncovered a Windows information-stealing malware campaign disguised as a legitimate AI application.

Known as RevStealer, the malware is delivered through a trojanized Electron desktop application that impersonates Anthropic’s Claude AI service.

The campaign uses a fake “Claude Opus 5 Free Desktop” project hosted through GitHub repositories and promoted on game-cheat-themed websites. The lure attempts to exploit growing interest in AI tools by promising free access to a paid AI model.

Once executed, RevStealer can collect sensitive information from browsers, password managers, cryptocurrency wallets, VPN applications and other software.

It also targets session cookies, Windows Credential Manager data, clipboard contents, screenshots and selected documents.

Read more on CyberPress