Skip to the card

Card 531 of 9972026-09-07 issue

Observed arrival · 2026-09-07

The Fake Claude App That Was Really RevStealer

netsecurity.top Observed source
Editorial interest 79/100 Selection signal · not a rating of the site

Credibility concern recorded. The source reference remains available for verification and correction.

A bilingual threat report examines a fake Claude Opus 5 desktop app that delivered Windows information-stealing malware.

Landing page captured for the 2026-09-07 issue.

Field notes

The report traces a specific social-engineering path through a GitHub repository using Claude Opus 5 branding and a free-access promise. Its technical account identifies a 101 MB ZIP, checks for memory, processors, hostname, username, and graphics hardware, then describes Defender-exclusion attempts before RevStealer runs in the background. The page also documents how stolen material is streamed rather than stored in one obvious archive and how the payload removes itself after execution.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

OpenPublic substance visible
PrettyNotable craft visible
ProPolished or operationally mature
RiskCredibility concern recorded

One card from the complete issue

A Record Press With a 0.4 mm Nozzle

278,515 arrived 1,000 judged 997 catalogued Enter the complete issue
netsecurity.top

Landing page observed 2026-09-07. The live site may have changed.