Observed arrival · 2026-09-07
The Fake Claude App That Was Really RevStealer
Credibility concern recorded. The source reference remains available for verification and correction.
A bilingual threat report examines a fake Claude Opus 5 desktop app that delivered Windows information-stealing malware.
Field notes
The report traces a specific social-engineering path through a GitHub repository using Claude Opus 5 branding and a free-access promise. Its technical account identifies a 101 MB ZIP, checks for memory, processors, hostname, username, and graphics hardware, then describes Defender-exclusion attempts before RevStealer runs in the background. The page also documents how stolen material is streamed rather than stored in one obvious archive and how the payload removes itself after execution.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue