A fake desktop application claiming to offer free access to Anthropic’s Claude is being used to distribute the RevStealer malware. This malicious software targets over 50 cryptocurrency wallets and also collects browser passwords, cookies, messaging data and selected documents. RevStealer checks if the infected machine resembles a real user device before triggering its malicious payload, analyzing available memory, processor core count and hostname. If the system passes these checks, the malware decrypts and executes its payload under a random name. This discovery follows Kaspersky’s finding of the OkoBot framework, another malware targeting cryptocurrency investors.
Source: Read the original article

