Hackers Disguise RevStealer as Claude Opus 5 AI App to Hijack Passwords and Crypto Wallets
Cybercriminals have begun distributing a Windows‑based malware known as RevStealer by masquerading it as a desktop version of the popular Claude Opus 5 AI tool. The deceptive application is packaged in a downloadable archive that promises users access to the latest generative‑AI capabilities, but instead installs software designed to harvest passwords, browser credentials and cryptocurrency wallet information.
RevStealer, a modular trojan that has appeared in previous campaigns, is engineered to capture a wide range of sensitive data from infected machines. Once installed, it can extract saved passwords from password managers, scrape browser autofill fields, and locate private keys or seed phrases stored on the device, giving attackers direct control over victims' digital assets.
The lure of a free or low‑cost Claude Opus 5 client is a calculated move by the threat actors. Demand for advanced AI assistants has surged among both professionals and hobbyists, and legitimate releases of such software are often limited or behind paywalls. By offering a counterfeit version, the attackers exploit this appetite, turning curiosity into a conduit for malware distribution.
Security researchers who first observed the campaign noted that the malicious archive is typically shared through file‑sharing sites, forums and social media platforms where AI enthusiasts congregate. The archive appears to contain an installer for the Claude Opus 5 desktop client, but the executable is actually a dropper that silently deploys RevStealer in the background. Users who run the installer may see a brief installation wizard before the trojan begins its data‑exfiltration routine.
Experts warn that the threat extends beyond immediate credential theft. By compromising cryptocurrency wallets, the malware can facilitate the rapid movement of stolen funds through mixers and other obfuscation services, making recovery difficult. Additionally, the harvested browser data can be leveraged for further phishing attacks or sold on underground markets.
Authorities and cybersecurity firms are urging users to download AI tools only from official vendor sites and to verify digital signatures where available. Employing reputable antivirus solutions, keeping operating systems up to date, and using hardware wallets for crypto storage are recommended mitigations. Users who suspect infection should disconnect from networks, run a thorough malware scan, and consider changing passwords on affected accounts.
The campaign underscores a broader trend of threat actors weaponizing the hype surrounding emerging technologies. As AI applications become more mainstream, security professionals anticipate that similar deceptive distribution tactics will continue to evolve, highlighting the need for heightened vigilance among both consumers and organizations.
Comments (0)
Be the first to comment.
Join the discussion