RevStealer Malware Targets Users via Fake AI Application

RevStealer Malware Targets Users via Fake AI Application

First seen 31 Aug 2026, 19:59 UTC MorphisecCyberinsider 64.5

Article Content

Browse articles
ThreatCluster

RevStealer is a Windows information stealer disguised as a legitimate Electron desktop application, specifically a fake version of Anthropic's Claude Opus 5. It has been distributed through GitHub repositories and game-cheat websites, with a notable lure being the 'Claude Opus 5 Free Desktop' project. The malware stealthily collects sensitive data, including browser databases, passwords, and cryptocurrency wallets, while employing anti-analysis techniques to evade detection. The infection begins when a user downloads a 101 MB archive, which contains an Electron application that executes without a visible interface. RevStealer performs checks on the host system to avoid detection and attempts to add its directory to Microsoft Defender's exclusion list. If the primary command-and-control (C2) server is unreachable, it retrieves a fallback address from a Polygon blockchain smart contract. The malware is designed for a single burst of data theft, leaving no traces post-exfiltration. Users are advised to avoid downloading unofficial software versions, especially from unverified sources.

Key Points: • RevStealer masquerades as a legitimate AI application to steal sensitive data. • The malware employs advanced anti-analysis techniques to evade detection. • Users are advised to avoid unofficial software downloads from unverified sources.

Timeline

2026-08-31
RevStealer malware identified
Morphisec reported on RevStealer, detailing its distribution via fake Claude Opus 5 applications.
Morphisec
2026-08-31
Cyberinsider reports on RevStealer
Cyberinsider confirmed the malware's distribution methods and its data theft capabilities.
Cyberinsider