๐Ÿ“… Friday, 4 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Malware Windows Menyamar Jadi Claude Gratis - Kuras 50 Dompet Kripto dan Hapus Jejak Sendiri

Windows Malware Disguised as Free Claude Drains 50 Crypto Wallets and Erases Own Traces

A 101 MB download is infiltrating Windows systems, targeting more than 50 types of crypto wallets, 12 password managers, and browser data. Disguised as a “Claude Opus 5 Free Desktop” app, the file delivers RevStealer malware that exfiltrates data and promptly deletes itself from the victim’s machine.

Cybersecurity firm Morphisec disclosed the findings in a report dated August 31, 2026. Threat actors initially distributed the malware through GitHub repositories and video game cheat websites. They later shifted their marketing tactics, leveraging Anthropic’s brand to lure fresh victims.

A Single Trace-Free Operation

Once a victim executes the 64-bit Electron app, no graphical interface appears on the Windows screen. RevStealer immediately deploys an AES-256-CBC encrypted payload in the background. The malware avoids creating scheduled tasks to establish long-term persistence. Instead, it operates as a one-time execution: harvesting data, transmitting it to operators, and self-destructing to evade antivirus detection.

RevStealer’s target list spans Windows Credential Manager, private VPN configurations, instant messaging application data, and screenshots of victim activity. The attackers also harvest browser session cookies, enabling hackers to hijack user accounts even when protected by multi-factor authentication.

Backup Servers on the Polygon Network

The hacking group maintains backup command-and-control servers inside smart contracts on the Polygon blockchain. This infrastructure allows them to switch the primary server address at any point without needing to redeploy new malware binaries to prospective victims.

RevStealer fortifies its operations with a ten-stage weighted check to distinguish legitimate victim machines from security researchers’ virtual environments. The malware verifies the availability of at least 2 GB of RAM, a dual-core CPU, and a physical graphics card. The malicious software also triggers a CAPTCHA prompt and performs timing checks on the JavaScript debugger. “Each stage was built on the assumption that someone was watching,” Morphisec researcher Shmuel Uzan said.

The data theft operation automatically aborts and the malware terminates itself if the operating system is set to Russian, Ukrainian, or several Central Asian languages. Such language exclusions are often used by hackers to avoid scrutiny from law enforcement in their home countries.

Reported by crypto.news.

Read also: Hacker Drains Nearly All TVL from Solana’s Aquifer - Given Three Days to Keep 20%


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share