A fake desktop application impersonating Anthropic's Claude AI assistant is being used to deliver malware capable of stealing cryptocurrency wallet credentials, according to research from cybersecurity firm Morphisec.
The malware, named RevStealer, is being distributed through an app calling itself "Claude Opus 5 Free Desktop." It targets Windows users and has previously circulated through GitHub repositories and websites offering video game cheats, Morphisec found.
For European users increasingly experimenting with AI tools and crypto wallets on the same machines, the campaign underscores how attackers are exploiting interest in generative AI to reach a broader pool of victims than traditional gaming-focused lures.
What the malware collects
According to Morphisec, RevStealer is built to harvest passwords, browser cookies and browser data, password manager entries, VPN program data, remote access software data, messages, screenshots and selected documents from infected machines. The firm said the malware is capable of targeting more than 50 different cryptocurrency wallets.
Before executing, RevStealer performs a series of checks designed to avoid detection by security researchers. It examines available memory, the number of processor cores, the username and the graphics hardware on the machine, looking for signs of a test or sandbox environment. If it detects such conditions, the attack is aborted. If not, the malware is saved under a random filename and runs unnoticed on the victim's system.
A second framework targeting wallets
Separately, researchers at Kaspersky identified another malware framework, called OkoBot, also aimed at cryptocurrency holders. According to Kaspersky, OkoBot collects cryptowallet files, browser data and other user information. The framework is also capable of installing malicious browser extensions and manipulating wallet application windows, according to the firm's findings.
Neither Morphisec nor Kaspersky has disclosed how many users have been affected by the two campaigns, and there is no confirmation of financial losses tied to either piece of malware.
The discoveries add to a growing pattern of malware operators repurposing the popularity of AI assistants as bait, alongside more established lures such as pirated software and gaming cheats, to gain access to victims' devices and, ultimately, their crypto holdings.




