吴说区块链|Sep 01, 2026 14:44
According to WuShuo, a report from Morphisec Threat Labs reveals that a Windows info-stealing malware called RevStealer is being distributed through a fake Claude desktop app. Researchers discovered that attackers had uploaded a download link on GitHub under the name 'Claude Opus 5 Free Desktop.' Once users run the app, it launches a hidden Electron loader, which deploys the malicious payload after detecting virtual machines, sandboxes, and debugging environments.
Morphisec states that RevStealer can steal data from Chromium and Firefox browsers, Windows credentials, password managers, VPNs, chat apps, documents, and targets 51 types of crypto wallets. The malware encrypts and exfiltrates stolen data in batches to minimize local traces. If the primary C2 server fails, it can retrieve backup server addresses via smart contracts on Polygon. Researchers noted that RevStealer does not establish conventional persistence mechanisms but instead focuses on completing data theft quickly before exiting.
https://(wublock123.com)/news/revstealer-disguised-as-claude-desktop-targets-51-crypto-wallets-11-password-managers-67612
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink